2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46840 | CRITICAL | 9.1 | 0.4% | Oct 14, 2022 | The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation ... |
| CVE-2021-46839 | CRITICAL | 9.1 | 0.4% | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerabil... |
| CVE-2021-20030 | HIGH | 7.5 | 0.8% | Oct 13, 2022 | SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web ... |
| CVE-2021-36369 | HIGH | 7.5 | 1.3% | Oct 12, 2022 | An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication me... |
| CVE-2021-36201 | MEDIUM | 5.3 | 0.5% | Oct 11, 2022 | Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versi... |
| CVE-2021-36915 | MEDIUM | 4.3 | 0.2% | Oct 11, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows upload... |
| CVE-2021-0951 | HIGH | 7.8 | 0.1% | Oct 11, 2022 | In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead... |
| CVE-2021-0696 | HIGH | 7 | 0.1% | Oct 11, 2022 | In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local e... |
| CVE-2021-36913 | HIGH | 7.5 | 0.5% | Oct 11, 2022 | Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= ... |
| CVE-2021-36899 | MEDIUM | 4.8 | 0.4% | Oct 11, 2022 | Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Boos... |
| CVE-2021-35226 | MEDIUM | 6.5 | 0.4% | Oct 10, 2022 | An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Informatio... |
| CVE-2021-25044 | MEDIUM | 6.1 | 0.5% | Oct 10, 2022 | The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage pa... |
| CVE-2021-44171 | HIGH | 8 | 1.5% | Oct 10, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version... |
| CVE-2021-40166 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has ... |
| CVE-2021-40165 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond th... |
| CVE-2021-40164 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploite... |
| CVE-2021-40163 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Imag... |
| CVE-2021-40162 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond a... |
| CVE-2021-40556 | HIGH | 8.8 | 1.3% | Oct 6, 2022 | A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulne... |
| CVE-2021-36865 | MEDIUM | 4.3 | 0.4% | Sep 30, 2022 | Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPres... |
| CVE-2021-33354 | HIGH | 8.1 | 1.3% | Sep 30, 2022 | Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via ... |
| CVE-2021-36855 | MEDIUM | 6.1 | 0.2% | Sep 30, 2022 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at W... |
| CVE-2021-36854 | HIGH | 8.8 | 0.3% | Sep 30, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress. |
| CVE-2021-36839 | MEDIUM | 4.8 | 0.4% | Sep 30, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73... |
| CVE-2021-36830 | MEDIUM | 4.8 | 0.4% | Sep 30, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now