2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45035 | MEDIUM | 5.9 | 0.4% | Sep 23, 2022 | Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could al... |
| CVE-2021-3782 | MEDIUM | 6.6 | 0.3% | Sep 23, 2022 | An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. Th... |
| CVE-2021-41803 | HIGH | 7.1 | 0.8% | Sep 23, 2022 | HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to inte... |
| CVE-2021-27774 | MEDIUM | 5.4 | 0.3% | Sep 22, 2022 | User input included in error response, which could be used in a phishing attack. |
| CVE-2021-39190 | MEDIUM | 5.3 | 0.4% | Sep 22, 2022 | The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3... |
| CVE-2021-43310 | CRITICAL | 9.8 | 1.7% | Sep 21, 2022 | A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys ... |
| CVE-2021-46835 | MEDIUM | 4.3 | 0.2% | Sep 20, 2022 | There is a traffic hijacking vulnerability in WS7200-10 11.0.2.13. Successful exploitation of this vulnerability can cau... |
| CVE-2021-46834 | MEDIUM | 5.5 | 0.2% | Sep 20, 2022 | A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resou... |
| CVE-2021-33081 | MEDIUM | 4.4 | 0.2% | Sep 20, 2022 | Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially en... |
| CVE-2021-33079 | MEDIUM | 4.4 | 0.2% | Sep 20, 2022 | Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially en... |
| CVE-2021-33076 | MEDIUM | 6.8 | 0.3% | Sep 20, 2022 | Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially e... |
| CVE-2021-46836 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th... |
| CVE-2021-40024 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th... |
| CVE-2021-40023 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality... |
| CVE-2021-40019 | CRITICAL | 9.1 | 0.5% | Sep 16, 2022 | Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may caus... |
| CVE-2021-40017 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may re... |
| CVE-2021-42597 | MEDIUM | 5.4 | 0.4% | Sep 16, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Storage Unit Rental Management System PHP 8.0.10 , A... |
| CVE-2021-41731 | MEDIUM | 4.8 | 0.7% | Sep 16, 2022 | Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQ... |
| CVE-2021-42948 | LOW | 3.7 | 0.7% | Sep 16, 2022 | HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links vi... |
| CVE-2021-42949 | CRITICAL | 9.8 | 5.5% | Sep 16, 2022 | The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session to... |
| CVE-2021-44076 | MEDIUM | 4.8 | 0.6% | Sep 15, 2022 | An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allow... |
| CVE-2021-38924 | HIGH | 7.5 | 0.8% | Sep 14, 2022 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a det... |
| CVE-2021-36568 | MEDIUM | 5.4 | 0.8% | Sep 13, 2022 | In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this cas... |
| CVE-2021-0943 | HIGH | 7.8 | 0.1% | Sep 13, 2022 | In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to loc... |
| CVE-2021-0942 | CRITICAL | 9.8 | 0.3% | Sep 13, 2022 | The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the u... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now