LiveActive security incident?Get immediate response
CVE archive

December 2021

Browse CVE records published in December 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2052 matching CVEs · Page 10 of 42.

Critical · CVSS 9.1

CVE-2021-43985: mySCADA myPRO

An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.

Published Dec 23, 2021 · Updated Sep 16, 2024

High · CVSS 7.8

CVE-2021-43982: Delta Electronics CNCSoft

Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.

Published Dec 9, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.7

CVE-2021-36317: Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller.

Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

Published Dec 21, 2021 · Updated Sep 16, 2024

High · CVSS 8.3

CVE-2021-36198: Entrapass

Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.

Published Dec 6, 2021 · Updated Sep 16, 2024

Medium · CVSS 4.4

CVE-2021-36721: Sysaid - Sysaid API User Enumeration

Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server.

Published Dec 14, 2021 · Updated Sep 16, 2024

Critical · CVSS 10

CVE-2021-23198: mySCADA myPRO

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

Published Dec 23, 2021 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2021-45907: An issue was discovered in gif2apng 1.9.

An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

Published Dec 28, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2021-45911: An issue was discovered in gif2apng 1.9.

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.

Published Dec 28, 2021 · Updated Aug 4, 2024