KEV 2021

213 CISA Known Exploited Vulnerabilities from 2021

CVE-2021-41277

Metabase Metabase — Metabase GeoJSON API Local File Inclusion Vulnerability

CVSS 10

CVE-2021-28799

QNAP Network Attached Storage (NAS) — QNAP NAS Improper Authorization Vulnerability

CVSS 10

CVE-2021-44228

Apache Log4j2 'Log4Shell' — JNDI Injection via Logged Input Allows Unauthenticated Remote Code Execution

CVSS 10

CVE-2021-22205

GitLab Community and Enterprise Editions — GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

CVSS 10

CVE-2021-22893

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Use-After-Free Vulnerability

CVSS 10

CVE-2021-30116

Kaseya Virtual System/Server Administrator (VSA) — Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

CVSS 10

CVE-2021-38163

SAP NetWeaver — SAP NetWeaver Unrestricted File Upload Vulnerability

CVSS 9.9

CVE-2021-22681

Rockwell Multiple Products — Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

CVSS 9.8

CVE-2021-32030

ASUS Routers — ASUS Routers Improper Authentication Vulnerability

CVSS 9.8

CVE-2021-33044

Dahua IP Camera Firmware — Dahua IP Camera Authentication Bypass Vulnerability

CVSS 9.8

CVE-2021-33045

Dahua IP Camera Firmware — Dahua IP Camera Authentication Bypass Vulnerability

CVSS 9.8

CVE-2021-44529

Ivanti EPM CSA — Unauthenticated Remote Code Execution via Backdoored csrf-magic PHP Library

CVSS 9.8

CVE-2021-36380

Sunhillo SureLine — Sunhillo SureLine OS Command Injection Vulnerablity

CVSS 9.8

CVE-2021-3129

Laravel Ignition — Laravel Ignition File Upload Vulnerability

CVSS 9.8

CVE-2021-44026

Roundcube Roundcube Webmail — Roundcube Webmail SQL Injection Vulnerability

CVSS 9.8

CVE-2021-35587

Oracle Fusion Middleware — Oracle Fusion Middleware Unspecified Vulnerability

CVSS 9.8

CVE-2021-39226

Grafana Labs Grafana — Grafana Authentication Bypass Vulnerability

CVSS 9.8

CVE-2021-27852

Checkbox Checkbox Survey — Checkbox Survey Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2021-31166

Microsoft HTTP Protocol Stack — Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-45382

D-Link Multiple Routers — D-Link Multiple Routers Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-20028

SonicWall Secure Remote Access (SRA) — SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability

CVSS 9.8

CVE-2021-22941

Citrix ShareFile — Citrix ShareFile Improper Access Control Vulnerability

CVSS 9.8

CVE-2021-42237

Sitecore XP — Sitecore XP Remote Command Execution Vulnerability

CVSS 9.8

CVE-2021-20038

SonicWall SMA 100 Appliances — SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability

CVSS 9.8

CVE-2021-22991

F5 BIG-IP Traffic Management Microkernel — F5 BIG-IP Traffic Management Microkernel Buffer Overflow

CVSS 9.8

CVE-2021-40870

Aviatrix Aviatrix Controller — Aviatrix Controller Unrestricted Upload of File

CVSS 9.8

CVE-2021-27860

FatPipe WARP, IPVPN, and MPVPN software — FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

CVSS 9.8

CVE-2021-36260

Hikvision Security cameras web server — Hikvision Improper Input Validation

CVSS 9.8

CVE-2021-35394

Realtek Jungle Software Development Kit (SDK) — Realtek Jungle SDK Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-44515

Zoho Desktop Central — Zoho Desktop Central Authentication Bypass Vulnerability

CVSS 9.8

CVE-2021-37415

Zoho ManageEngine ServiceDesk Plus (SDP) — Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

CVSS 9.8

CVE-2021-44077

Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus — Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-1497

Cisco HyperFlex HX — Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

CVSS 9.8

CVE-2021-1498

Cisco HyperFlex HX — Cisco HyperFlex HX Data Platform Command Injection Vulnerability

CVSS 9.8

CVE-2021-1870

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-1871

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-20016

SonicWall SSLVPN SMA100 — SonicWall SSLVPN SMA100 SQL Injection Vulnerability

CVSS 9.8

CVE-2021-20021

SonicWall SonicWall Email Security — SonicWall Email Security Improper Privilege Management Vulnerability

CVSS 9.8

CVE-2021-20090

Arcadyan Buffalo Firmware — Arcadyan Buffalo Firmware Path Traversal Vulnerability

CVSS 9.8

CVE-2021-21972

VMware vCenter Server — VMware vCenter Server Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-21985

VMware vCenter Server — VMware vCenter Server Improper Input Validation Vulnerability

CVSS 9.8

CVE-2021-22005

VMware vCenter Server — VMware vCenter Server File Upload Vulnerability

CVSS 9.8

CVE-2021-22502

Micro Focus Operation Bridge Reporter (OBR) — Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-22986

F5 BIG-IP and BIG-IQ Centralized Management — F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-26084

Atlassian Confluence Server and Data Center — Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVSS 9.8

CVE-2021-27101

Accellion FTA — Accellion FTA SQL Injection Vulnerability

CVSS 9.8

CVE-2021-27103

Accellion FTA — Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

CVSS 9.8

CVE-2021-27104

Accellion FTA — Accellion FTA OS Command Injection Vulnerability

CVSS 9.8

CVE-2021-27561

Yealink Device Management — Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability

CVSS 9.8

CVE-2021-31755

Tenda AC11 Router — Tenda AC11 Router Stack Buffer Overflow Vulnerability

CVSS 9.8

CVE-2021-35395

Realtek AP-Router SDK — Realtek AP-Router SDK Buffer Overflow Vulnerability

CVSS 9.8

CVE-2021-35464

ForgeRock Access Management (AM) — ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-38647

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVSS 9.8

CVE-2021-40539

Zoho ManageEngine — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

CVSS 9.8

CVE-2021-41773

Apache HTTP Server — Apache HTTP Server Path Traversal Vulnerability

CVSS 9.8

CVE-2021-42013

Apache HTTP Server — Apache HTTP Server Path Traversal Vulnerability

CVSS 9.8

CVE-2021-42258

BQE BillQuick Web Suite — BQE BillQuick Web Suite SQL Injection Vulnerability

CVSS 9.8

CVE-2021-30633

Google Chromium Indexed DB API — Google Chromium Indexed DB API Use-After-Free Vulnerability

CVSS 9.6

CVE-2021-37973

Google Chromium Portals — Google Chromium Portals Use-After-Free Vulnerability

CVSS 9.6

CVE-2021-26855

Microsoft Exchange Server 'ProxyLogon' — SSRF Authentication Bypass Enables Pre-Auth RCE; Exploited as Zero-Day by HAFNIUM

CVSS 9.1

CVE-2021-34473

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 9.1

CVE-2021-45046

Apache Log4j2 — Apache Log4j2 Deserialization of Untrusted Data Vulnerability

CVSS 9

CVE-2021-40438

Apache Apache — Apache HTTP Server-Side Request Forgery (SSRF)

CVSS 9

CVE-2021-34523

Microsoft Exchange Server — Microsoft Exchange Server Privilege Escalation Vulnerability

CVSS 9

CVE-2021-35211

SolarWinds Serv-U — SolarWinds Serv-U Remote Code Execution Vulnerability

CVSS 9

CVE-2021-26828

OpenPLC ScadaBR — OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability

CVSS 8.8

CVE-2021-29256

Arm Mali Graphics Processing Unit (GPU) — Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-27878

Veritas Backup Exec Agent — Veritas Backup Exec Agent Command Execution Vulnerability

CVSS 8.8

CVE-2021-3493

Ubuntu Linux Kernel — overlayfs File Capabilities Bypass in User Namespaces for Local Privilege Escalation

CVSS 8.8

CVE-2021-1789

Apple Multiple Products — Apple Multiple Products Type Confusion Vulnerability

CVSS 8.8

CVE-2021-21551

Dell dbutil Driver — Dell dbutil Driver Insufficient Access Control Vulnerability

CVSS 8.8

CVE-2021-25296

Nagios Nagios XI — Nagios XI OS Command Injection

CVSS 8.8

CVE-2021-25297

Nagios Nagios XI — Nagios XI OS Command Injection

CVSS 8.8

CVE-2021-25298

Nagios Nagios XI — Nagios XI OS Command Injection

CVSS 8.8

CVE-2021-4102

Google Chromium V8 — Google Chromium V8 Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-42321

Microsoft Exchange — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 8.8

CVE-2021-21017

Adobe Acrobat and Reader — Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

CVSS 8.8

CVE-2021-21148

Google Chromium V8 — Google Chromium V8 Heap Buffer Overflow Vulnerability

CVSS 8.8

CVE-2021-21166

Google Chromium — Google Chromium Race Condition Vulnerability

CVSS 8.8

CVE-2021-21193

Google Chromium Blink — Google Chromium Blink Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-21206

Google Chromium Blink — Google Chromium Blink Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-21220

Google Chromium V8 — Google Chromium V8 Improper Input Validation Vulnerability

CVSS 8.8

CVE-2021-21224

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2021-22894

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

CVSS 8.8

CVE-2021-22899

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Command Injection Vulnerability

CVSS 8.8

CVE-2021-26411

Microsoft Internet Explorer — Microsoft Internet Explorer Memory Corruption Vulnerability

CVSS 8.8

CVE-2021-27085

Microsoft Internet Explorer — Microsoft Internet Explorer Remote Code Execution Vulnerability

CVSS 8.8

CVE-2021-28550

Adobe Acrobat and Reader — Adobe Acrobat and Reader Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-28663

Arm Mali Graphics Processing Unit (GPU) — Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-28664

Arm Mali Graphics Processing Unit (GPU) — Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability

CVSS 8.8

CVE-2021-30551

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2021-30554

Google Chromium WebGL — Google Chromium WebGL Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-30563

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2021-30632

Google Chromium V8 — Google Chromium V8 Out-of-Bounds Write Vulnerability

CVSS 8.8

CVE-2021-30661

Apple Multiple Products — Apple Multiple Products WebKit Storage Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-30663

Apple Multiple Products — Apple Multiple Products WebKit Integer Overflow Vulnerability

CVSS 8.8

CVE-2021-30665

Apple Multiple Products — Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 8.8

CVE-2021-30666

Apple iOS — Apple iOS WebKit Buffer Overflow Vulnerability

CVSS 8.8

CVE-2021-30761

Apple iOS — Apple iOS WebKit Memory Corruption Vulnerability

CVSS 8.8

CVE-2021-30762

Apple iOS — Apple iOS WebKit Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-30858

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, macOS Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-34527

Microsoft Windows 'PrintNightmare' — Print Spooler Driver Installation Allows Authenticated Remote Code Execution as SYSTEM

CVSS 8.8

CVE-2021-36741

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security — Trend Micro Multiple Products Improper Input Validation Vulnerability

CVSS 8.8

CVE-2021-37975

Google Chromium V8 — Google Chromium V8 Use-After-Free Vulnerability

CVSS 8.8

CVE-2021-38003

Google Chromium V8 — Google Chromium V8 Memory Corruption Vulnerability

CVSS 8.8

CVE-2021-40444

Microsoft MSHTML — Microsoft MSHTML Remote Code Execution Vulnerability

CVSS 8.8

CVE-2021-39144

XStream XStream — XStream Remote Code Execution Vulnerability

CVSS 8.5

CVE-2021-1905

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use-After-Free Vulnerability

CVSS 8.4

CVE-2021-33739

Microsoft Windows — Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

CVSS 8.4

CVE-2021-22555

Linux Kernel — Linux Kernel Heap Out-of-Bounds Write Vulnerability

CVSS 8.3

CVE-2021-27877

Veritas Backup Exec Agent — Veritas Backup Exec Agent Improper Authentication Vulnerability

CVSS 8.2

CVE-2021-32648

October CMS October CMS — October CMS Improper Authentication

CVSS 8.2

CVE-2021-23874

McAfee McAfee Total Protection (MTP) — McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

CVSS 8.2

CVE-2021-44207

Acclaim Systems USAHERDS — Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability

CVSS 8.1

CVE-2021-27876

Veritas Backup Exec Agent — Veritas Backup Exec Agent File Access Vulnerability

CVSS 8.1

CVE-2021-30952

Apple Multiple Products — Apple Multiple Products Integer Overflow or Wraparound Vulnerability

CVSS 7.8

CVE-2021-43226

Microsoft Windows — Microsoft Windows Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-3560

Red Hat Polkit — Red Hat Polkit Incorrect Authorization Vulnerability

CVSS 7.8

CVE-2021-30900

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

CVSS 7.8

CVE-2021-38406

Delta Electronics DOPSoft 2 — Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability

CVSS 7.8

CVE-2021-30983

Apple iOS and iPadOS — Apple iOS and iPadOS Buffer Overflow Vulnerability

CVSS 7.8

CVE-2021-4034

Polkit pkexec 'PwnKit' — Out-of-Bounds Write in Argument Handling Permits Root Escalation on Every Major Linux Distribution

CVSS 7.8

CVE-2021-1048

Android Kernel — Android Kernel Use-After-Free Vulnerability

CVSS 7.8

CVE-2021-30883

Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability

CVSS 7.8

CVE-2021-40450

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-41357

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-39793

Google Pixel — Google Pixel Out-of-Bounds Write Vulnerability

CVSS 7.8

CVE-2021-3156

Sudo 'Baron Samedit' — Heap-Based Buffer Overflow via Off-by-One Permits Root Escalation Without Any sudoers Entry

CVSS 7.8

CVE-2021-34484

Microsoft Windows — Microsoft Windows User Profile Service Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-34486

Microsoft Windows — Microsoft Windows Event Tracing Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-38646

Microsoft Office — Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

CVSS 7.8

CVE-2021-36934

Microsoft Windows — Microsoft Windows SAM Local Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-40449

Microsoft Windows — Microsoft Windows Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-42292

Microsoft Office — Microsoft Excel Security Feature Bypass

CVSS 7.8

CVE-2021-1647

Microsoft Defender — Microsoft Defender Remote Code Execution Vulnerability

CVSS 7.8

CVE-2021-1675

Microsoft Windows — Microsoft Windows Print Spooler Remote Code Execution Vulnerability

CVSS 7.8

CVE-2021-1732

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-26857

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8

CVE-2021-26858

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8

CVE-2021-27065

Microsoft Exchange Server — Microsoft Exchange Server Remote Code Execution Vulnerability

CVSS 7.8

CVE-2021-27102

Accellion FTA — Accellion FTA OS Command Injection Vulnerability

CVSS 7.8

CVE-2021-28310

Microsoft Win32k — Microsoft Win32k Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-30713

Apple macOS — Apple macOS Unspecified Vulnerability

CVSS 7.8

CVE-2021-30807

Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability

CVSS 7.8

CVE-2021-30860

Apple Multiple Products — Apple Multiple Products Integer Overflow Vulnerability

CVSS 7.8

CVE-2021-30869

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS Type Confusion Vulnerability

CVSS 7.8

CVE-2021-31956

Microsoft Windows — Microsoft Windows NTFS Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-31979

Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-33771

Microsoft Windows — Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-36742

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security — Trend Micro Multiple Products Improper Input Validation Vulnerability

CVSS 7.8

CVE-2021-36948

Microsoft Windows — Microsoft Windows Update Medic Service Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-36955

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-38645

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-38648

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 7.8

CVE-2021-27059

Microsoft Office — Microsoft Office Remote Code Execution Vulnerability

CVSS 7.6

CVE-2021-22054

Omnissa Workspace One UEM — Omnissa Workspace ONE Server-Side Request Forgery

CVSS 7.5

CVE-2021-43798

Grafana Labs Grafana — Grafana Path Traversal Vulnerability

CVSS 7.5

CVE-2021-20123

DrayTek VigorConnect — Draytek VigorConnect Path Traversal Vulnerability

CVSS 7.5

CVE-2021-20124

DrayTek VigorConnect — Draytek VigorConnect Path Traversal Vulnerability

CVSS 7.5

CVE-2021-40655

D-Link DIR-605 Router — D-Link DIR-605 Router Information Disclosure Vulnerability

CVSS 7.5

CVE-2021-31010

Apple iOS, macOS, watchOS — Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability

CVSS 7.5

CVE-2021-42278

Microsoft Active Directory — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

CVSS 7.5

CVE-2021-42287

Microsoft Active Directory — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

CVSS 7.5

CVE-2021-21975

VMware vRealize Operations Manager API — VMware Server Side Request Forgery in vRealize Operations Manager API

CVSS 7.5

CVE-2021-22506

Micro Focus Micro Focus Access Manager — Micro Focus Access Manager Information Leakage Vulnerability

CVSS 7.5

CVE-2021-33742

Microsoft Windows — Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

CVSS 7.5

CVE-2021-36942

Microsoft Windows — Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability

CVSS 7.5

CVE-2021-25487

Samsung Mobile Devices — Samsung Mobile Devices Out-of-Bounds Read Vulnerability

CVSS 7.3

CVE-2021-33766

Microsoft Exchange Server — Microsoft Exchange Server Information Disclosure

CVSS 7.3

CVE-2021-21311

Adminer Adminer — Adminer Server-Side Request Forgery Vulnerability

CVSS 7.2

CVE-2021-40407

Reolink RLC-410W IP Camera — Reolink RLC-410W IP Camera OS Command Injection Vulnerability

CVSS 7.2

CVE-2021-31196

Microsoft Exchange Server — Microsoft Exchange Server Information Disclosure Vulnerability

CVSS 7.2

CVE-2021-20022

SonicWall SonicWall Email Security — SonicWall Email Security Unrestricted Upload of File Vulnerability

CVSS 7.2

CVE-2021-22900

Ivanti Pulse Connect Secure — Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

CVSS 7.2

CVE-2021-21315

Npm package System Information Library for Node.JS — System Information Library for Node.JS Command Injection

CVSS 7.1

CVE-2021-43890

Microsoft Windows — Microsoft Windows AppX Installer Spoofing Vulnerability

CVSS 7.1

CVE-2021-1782

Apple Multiple Products — Apple Multiple Products Race Condition Vulnerability

CVSS 7

CVE-2021-38649

Microsoft Open Management Infrastructure (OMI) — Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability

CVSS 7

CVE-2021-22175

GitLab GitLab — GitLab Server-Side Request Forgery (SSRF) Vulnerability

CVSS 6.8

CVE-2021-39935

GitLab Community and Enterprise Editions — GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

CVSS 6.8

CVE-2021-22204

Perl Exiftool — ExifTool Remote Code Execution Vulnerability

CVSS 6.8

CVE-2021-34448

Microsoft Windows — Microsoft Windows Scripting Engine Memory Corruption Vulnerability

CVSS 6.8

CVE-2021-22600

Linux Kernel — Linux Kernel Privilege Escalation Vulnerability

CVSS 6.6

CVE-2021-31207

Microsoft Exchange Server — Microsoft Exchange Server Security Feature Bypass Vulnerability

CVSS 6.6

CVE-2021-20035

SonicWall SMA100 Appliances — SonicWall SMA100 Appliances OS Command Injection Vulnerability

CVSS 6.5

CVE-2021-30533

Google Chromium PopupBlocker — Google Chromium PopupBlocker Security Bypass Vulnerability

CVSS 6.5

CVE-2021-37976

Google Chromium — Google Chromium Information Disclosure Vulnerability

CVSS 6.5

CVE-2021-25394

Samsung Mobile Devices — Samsung Mobile Devices Race Condition Vulnerability

CVSS 6.4

CVE-2021-25395

Samsung Mobile Devices — Samsung Mobile Devices Race Condition Vulnerability

CVSS 6.4

CVE-2021-0920

Android Kernel — Android Kernel Race Condition Vulnerability

CVSS 6.4

CVE-2021-25369

Samsung Mobile Devices — Samsung Mobile Devices Improper Access Control Vulnerability

CVSS 6.2

CVE-2021-1906

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability

CVSS 6.2

CVE-2021-25371

Samsung Mobile Devices — Samsung Mobile Devices Unspecified Vulnerability

CVSS 6.1

CVE-2021-25372

Samsung Mobile Devices — Samsung Mobile Devices Improper Boundary Check Vulnerability

CVSS 6.1

CVE-2021-25370

Samsung Mobile Devices — Samsung Mobile Devices Memory Corruption Vulnerability

CVSS 6.1

CVE-2021-1879

Apple iOS, iPadOS, and watchOS — Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability

CVSS 6.1

CVE-2021-38000

Google Chromium Intents — Google Chromium Intents Improper Input Validation Vulnerability

CVSS 6.1

CVE-2021-41379

Microsoft Windows — Microsoft Windows Installer Privilege Escalation Vulnerability

CVSS 5.5

CVE-2021-27562

Arm Trusted Firmware — Arm Trusted Firmware Out-of-Bounds Write Vulnerability

CVSS 5.5

CVE-2021-30657

Apple macOS — Apple macOS Unspecified Vulnerability

CVSS 5.5

CVE-2021-31955

Microsoft Windows — Microsoft Windows Kernel Information Disclosure Vulnerability

CVSS 5.5

CVE-2021-26829

OpenPLC ScadaBR — OpenPLC ScadaBR Cross-site Scripting Vulnerability

CVSS 5.4

CVE-2021-26086

Atlassian Jira Server and Data Center — Atlassian Jira Server and Data Center Path Traversal Vulnerability

CVSS 5.3

CVE-2021-26085

Atlassian Confluence Server — Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

CVSS 5.3

CVE-2021-21973

VMware vCenter Server and Cloud Foundation — VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

CVSS 5.3

CVE-2021-22017

VMware vCenter Server — VMware vCenter Server Improper Access Control

CVSS 5.3

CVE-2021-31199

Microsoft Enhanced Cryptographic Provider — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVSS 5.2

CVE-2021-31201

Microsoft Enhanced Cryptographic Provider — Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability

CVSS 5.2

CVE-2021-20023

SonicWall SonicWall Email Security — SonicWall Email Security Path Traversal Vulnerability

CVSS 4.9

CVE-2021-25337

Samsung Mobile Devices — Samsung Mobile Devices Improper Access Control Vulnerability

CVSS 4.4

CVE-2021-35247

SolarWinds Serv-U — SolarWinds Serv-U Improper Input Validation Vulnerability

CVSS 4.3

CVE-2021-25489

Samsung Mobile Devices — Samsung Mobile Devices Improper Input Validation Vulnerability

CVSS 3.3

CVE-2021-44168

Fortinet FortiOS — Fortinet FortiOS Arbitrary File Download

CVSS 3.3