2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45476 | MEDIUM | 4.7 | 0.4% | Oct 27, 2022 | Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnera... |
| CVE-2021-45475 | MEDIUM | 5.3 | 0.5% | Oct 27, 2022 | Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosur... |
| CVE-2021-4228 | HIGH | 7.4 | 9.9% | Oct 24, 2022 | Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the ... |
| CVE-2021-46850 | HIGH | 7.2 | 5.2% | Oct 24, 2022 | myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An... |
| CVE-2021-46849 | — | — | — | Oct 24, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29421. Reason: This candidate is a duplicate of ... |
| CVE-2021-46848 | CRITICAL | 9.1 | 2.1% | Oct 24, 2022 | GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. |
| CVE-2021-46279 | HIGH | 8.8 | 0.4% | Oct 24, 2022 | Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attac... |
| CVE-2021-45925 | MEDIUM | 5.3 | 0.5% | Oct 24, 2022 | Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. Th... |
| CVE-2021-44776 | MEDIUM | 5.3 | 0.4% | Oct 24, 2022 | A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbit... |
| CVE-2021-44769 | MEDIUM | 6.5 | 0.4% | Oct 24, 2022 | An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Deni... |
| CVE-2021-44467 | HIGH | 7.5 | 0.7% | Oct 24, 2022 | A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrari... |
| CVE-2021-42010 | CRITICAL | 9.8 | 1.5% | Oct 24, 2022 | Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Ple... |
| CVE-2021-26733 | HIGH | 7.5 | 0.7% | Oct 24, 2022 | A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to a... |
| CVE-2021-26732 | MEDIUM | 5.3 | 0.4% | Oct 24, 2022 | A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitr... |
| CVE-2021-26731 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest... |
| CVE-2021-26730 | CRITICAL | 9.8 | 1.0% | Oct 24, 2022 | A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allow... |
| CVE-2021-26729 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_re... |
| CVE-2021-26728 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice all... |
| CVE-2021-26727 | CRITICAL | 9.8 | 2.3% | Oct 24, 2022 | Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_... |
| CVE-2021-42553 | CRITICAL | 9.8 | 1.0% | Oct 21, 2022 | A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker t... |
| CVE-2021-33231 | MEDIUM | 5.4 | 0.6% | Oct 20, 2022 | Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote a... |
| CVE-2021-3305 | HIGH | 7.8 | 0.3% | Oct 18, 2022 | Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability. |
| CVE-2021-27406 | HIGH | 8.8 | 0.9% | Oct 14, 2022 | An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any a... |
| CVE-2021-22685 | HIGH | 7.5 | 0.6% | Oct 14, 2022 | An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controll... |
| CVE-2021-0699 | HIGH | 7.8 | 0.1% | Oct 14, 2022 | In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now