Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2021-22204 | ExifTool Remote Code Execution Vulnerability | HIGH | N/A | 99.98% | cvelistv5 | 2021-11-17 |
| cve-2021-22175 | GitLab Server-Side Request Forgery (SSRF) Vulnerability | MEDIUM | 6.8 | 53.37% | cvelistv5 | 2026-02-18 |
| cve-2021-22122 | CVE-2021-22122 | HIGH | N/A | 10.52% | cvelistv5 | |
| cve-2021-22054 | Omnissa Workspace ONE Server-Side Request Forgery | HIGH | N/A | 99.68% | cvelistv5 | 2026-03-09 |
| cve-2021-22053 | Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution. | HIGH | 8.8 | 13.23% | cvelistv5 | 2026-06-17 |
| cve-2021-22017 | VMware vCenter Server Improper Access Control | MEDIUM | 5.3 | 49.18% | cvelistv5 | 2022-01-10 |
| cve-2021-22005 | VMware vCenter Server File Upload Vulnerability | CRITICAL | 9.8 | 100.00% | cvelistv5 | 2021-11-03 |
| cve-2021-21985 | VMware vCenter Server Improper Input Validation Vulnerability | CRITICAL | 9.8 | 100.00% | cvelistv5 | 2021-11-03 |
| cve-2021-21978 | CVE-2021-21978 | HIGH | N/A | 99.00% | cvelistv5 | |
| cve-2021-21975 | VMware Server Side Request Forgery in vRealize Operations Manager API | HIGH | 7.5 | 78.29% | cvelistv5 | 2022-01-18 |
| cve-2021-21973 | VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability | MEDIUM | 5.3 | 87.64% | cvelistv5 | 2022-03-07 |
| cve-2021-21972 | VMware vCenter Server Remote Code Execution Vulnerability | CRITICAL | 9.8 | 99.87% | cvelistv5 | 2021-11-03 |
| cve-2021-21805 | CVE-2021-21805 | CRITICAL | 9.8 | 69.84% | cvelistv5 | |
| cve-2021-21745 | CVE-2021-21745 | HIGH | N/A | 55.71% | cvelistv5 | |
| cve-2021-21551 | Dell dbutil Driver Insufficient Access Control Vulnerability | HIGH | 8.8 | 79.25% | cvelistv5 | 2022-03-31 |
| cve-2021-21479 | CVE-2021-21479 | HIGH | 8.1 | 10.12% | cvelistv5 | |
| cve-2021-21402 | Unauthenticated Arbitrary File Access in Jellyfin | HIGH | 7.7 | 79.31% | cvelistv5 | 2026-06-17 |
| cve-2021-21389 | CVE-2021-21389 | HIGH | 8.1 | 13.52% | cvelistv5 | |
| cve-2021-21315 | System Information Library for Node.JS Command Injection | HIGH | 7.1 | 90.67% | cvelistv5 | 2022-01-18 |
| cve-2021-21311 | Adminer Server-Side Request Forgery Vulnerability | HIGH | N/A | 98.46% | cvelistv5 | 2025-09-29 |
| cve-2021-21307 | CVE-2021-21307 | HIGH | 8.6 | 89.19% | cvelistv5 | |
| cve-2021-21234 | Directory Traversal | HIGH | 7.7 | 21.01% | cvelistv5 | 2026-06-17 |
| cve-2021-21224 | Google Chromium V8 Type Confusion Vulnerability | HIGH | N/A | 84.17% | cvelistv5 | 2021-11-03 |
| cve-2021-21220 | SUSE CVE CVE-2021-21220 | HIGH | 8.8 | 70.44% | cvelistv5 | 2025-03-15 |
| cve-2021-21206 | SUSE CVE CVE-2021-21206 | HIGH | 8.8 | 9.31% | cvelistv5 | 2025-03-15 |
| cve-2021-21193 | Google Chromium Blink Use-After-Free Vulnerability | HIGH | N/A | 9.87% | cvelistv5 | 2021-11-03 |
| cve-2021-21166 | Google Chromium Race Condition Vulnerability | HIGH | N/A | 24.03% | cvelistv5 | 2021-11-03 |
| cve-2021-21148 | Google Chromium V8 Heap Buffer Overflow Vulnerability | HIGH | N/A | 19.97% | cvelistv5 | 2021-11-03 |
| cve-2021-21087 | CVE-2021-21087 | MEDIUM | 5.4 | 37.09% | cvelistv5 | |
| cve-2021-21017 | Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability | HIGH | 8.8 | 86.33% | cvelistv5 | 2021-11-03 |