2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46851 | CRITICAL | 9.8 | 0.5% | Nov 9, 2022 | The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerabil... |
| CVE-2021-34569 | CRITICAL | 9.8 | 0.8% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to... |
| CVE-2021-34566 | CRITICAL | 9.1 | 1.0% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co... |
| CVE-2021-40241 | CRITICAL | 9.8 | 1.0% | Oct 31, 2022 | xfig 3.2.7 is vulnerable to Buffer Overflow. |
| CVE-2021-42777 | CRITICAL | 9.8 | 1.0% | Oct 29, 2022 | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrar... |
| CVE-2021-38733 | CRITICAL | 9.8 | 0.6% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. |
| CVE-2021-38732 | CRITICAL | 9.8 | 0.7% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. |
| CVE-2021-38731 | CRITICAL | 9.8 | 0.6% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. |
| CVE-2021-38730 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. |
| CVE-2021-38729 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. |
| CVE-2021-38217 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. |
| CVE-2021-38737 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php. |
| CVE-2021-38736 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. |
| CVE-2021-38734 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. |
| CVE-2021-37782 | CRITICAL | 9.8 | 0.8% | Oct 28, 2022 | Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php. |
| CVE-2021-38397 | CRITICAL | 10 | 0.9% | Oct 28, 2022 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may all... |
| CVE-2021-38395 | CRITICAL | 9.8 | 0.9% | Oct 28, 2022 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special eleme... |
| CVE-2021-46848 | CRITICAL | 9.1 | 2.1% | Oct 24, 2022 | GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. |
| CVE-2021-42010 | CRITICAL | 9.8 | 1.5% | Oct 24, 2022 | Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Ple... |
| CVE-2021-26731 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest... |
| CVE-2021-26730 | CRITICAL | 9.8 | 1.0% | Oct 24, 2022 | A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allow... |
| CVE-2021-26729 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_re... |
| CVE-2021-26728 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice all... |
| CVE-2021-26727 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_... |
| CVE-2021-42553 | CRITICAL | 9.8 | 1.0% | Oct 21, 2022 | A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now