2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34569 | CRITICAL | 9.8 | 0.8% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to... |
| CVE-2021-34568 | HIGH | 7.5 | 1.0% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co... |
| CVE-2021-34567 | HIGH | 8.2 | 0.8% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co... |
| CVE-2021-34566 | CRITICAL | 9.1 | 1.0% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co... |
| CVE-2021-39661 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a miss... |
| CVE-2021-1050 | HIGH | 7.8 | 0.2% | Nov 8, 2022 | In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. T... |
| CVE-2021-40303 | MEDIUM | 5.4 | 0.5% | Nov 8, 2022 | perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile. |
| CVE-2021-42205 | MEDIUM | 4.7 | 0.3% | Nov 7, 2022 | ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows loca... |
| CVE-2021-39473 | MEDIUM | 5.4 | 0.6% | Nov 4, 2022 | Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and conta... |
| CVE-2021-39432 | MEDIUM | 6.5 | 0.7% | Nov 4, 2022 | diplib v3.0.0 is vulnerable to Double Free. |
| CVE-2021-34055 | HIGH | 7.8 | 0.4% | Nov 4, 2022 | jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u. |
| CVE-2021-41576 | — | — | — | Nov 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves... |
| CVE-2021-41575 | — | — | — | Nov 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves... |
| CVE-2021-41574 | — | — | — | Nov 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves... |
| CVE-2021-34686 | — | — | — | Nov 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves... |
| CVE-2021-44862 | HIGH | 7.8 | 0.2% | Nov 3, 2022 | Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information sto... |
| CVE-2021-39077 | MEDIUM | 4.4 | 0.1% | Nov 3, 2022 | IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can... |
| CVE-2021-36906 | HIGH | 8.8 | 0.5% | Nov 3, 2022 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 ... |
| CVE-2021-37823 | MEDIUM | 4.9 | 0.7% | Nov 3, 2022 | OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the backgroun... |
| CVE-2021-46853 | MEDIUM | 5.9 | 0.8% | Nov 3, 2022 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent be... |
| CVE-2021-45448 | MEDIUM | 6.5 | 0.6% | Nov 2, 2022 | Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a ser... |
| CVE-2021-45447 | HIGH | 7.5 | 0.3% | Nov 2, 2022 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage ... |
| CVE-2021-45446 | HIGH | 7.5 | 0.4% | Nov 2, 2022 | A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not ca... |
| CVE-2021-37789 | HIGH | 8.1 | 0.8% | Nov 2, 2022 | stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service... |
| CVE-2021-27784 | HIGH | 7.5 | 0.2% | Oct 31, 2022 | The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now