Skip to main content

Year archive

CVEs published in 2021

Archive summary

20,149 CVEs published in 2021 — 2,558 Critical, 8,477 High, 8,471 Medium, 643 Low, 0 Unrated.

CVE-2021-1051

Published Jan 8, 2021

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36049

Published Jan 8, 2021

socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36048

Published Jan 8, 2021

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13452

Published Jan 7, 2021

In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13451

Published Jan 7, 2021

An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13450

Published Jan 7, 2021

A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. T…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-13449

Published Jan 7, 2021

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35745

Published Jan 7, 2021

PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18643

Published Jan 7, 2021

Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application. The only protection mechanism is a file-extension blacklis…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18642

Published Jan 7, 2021

Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile update feature. The lack of validation and use of sequential u…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-6656

Published Jan 7, 2021

Eaton's easySoft software v7.xx prior to v7.22 are susceptible to file parsing type confusion remote code execution vulnerability. A malicious entity can execute a malicious code…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6655

Published Jan 7, 2021

The Eaton's easySoft software v7.xx prior to v7.22 are susceptible to Out-of-bounds remote code execution vulnerability. A malicious entity can execute a malicious code or make th…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4898

Published Jan 7, 2021

IBM Emptoris Strategic Supply Management 10.1.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Forc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4896

Published Jan 7, 2021

IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 19098…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4895

Published Jan 7, 2021

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript cod…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4893

Published Jan 7, 2021

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4892

Published Jan 7, 2021

IBM Emptoris Contract Management 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27835

Published Jan 7, 2021

A use after free in the Linux kernel infiniband hfi1 driver in versions prior to 5.10-rc6 was found in the way user calls Ioctl after open dev file and fork. A local user could us…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25680

Published Jan 7, 2021

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate w…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13573

Published Jan 7, 2021

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request c…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 19,901-19,925 of 20,149 CVEsPage 797 of 806