2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46840 | CRITICAL | 9.1 | 0.4% | Oct 14, 2022 | The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation ... |
| CVE-2021-46839 | CRITICAL | 9.1 | 0.4% | Oct 14, 2022 | The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerabil... |
| CVE-2021-45790 | CRITICAL | 9.8 | 1.9% | Sep 29, 2022 | An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to ar... |
| CVE-2021-41433 | CRITICAL | 9.8 | 0.9% | Sep 27, 2022 | SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application logi... |
| CVE-2021-43310 | CRITICAL | 9.8 | 1.7% | Sep 21, 2022 | A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys ... |
| CVE-2021-40019 | CRITICAL | 9.1 | 0.5% | Sep 16, 2022 | Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may caus... |
| CVE-2021-40017 | CRITICAL | 9.8 | 0.5% | Sep 16, 2022 | The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may re... |
| CVE-2021-42949 | CRITICAL | 9.8 | 5.5% | Sep 16, 2022 | The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session to... |
| CVE-2021-0942 | CRITICAL | 9.8 | 0.3% | Sep 13, 2022 | The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the u... |
| CVE-2021-44835 | CRITICAL | 9.8 | 0.9% | Sep 9, 2022 | An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanit... |
| CVE-2021-34236 | CRITICAL | 9.8 | 1.1% | Sep 8, 2022 | Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cau... |
| CVE-2021-36783 | CRITICAL | 9.9 | 0.6% | Sep 7, 2022 | A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Member... |
| CVE-2021-36782 | CRITICAL | 9.9 | 2.9% | Sep 7, 2022 | A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster ... |
| CVE-2021-27693 | CRITICAL | 9.8 | 0.9% | Sep 2, 2022 | Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the ... |
| CVE-2021-43329 | CRITICAL | 9.8 | 2.3% | Aug 25, 2022 | A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac... |
| CVE-2021-39815 | CRITICAL | 9.8 | 0.4% | Aug 24, 2022 | The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre... |
| CVE-2021-42627 | CRITICAL | 9.8 | 67.9% | Aug 23, 2022 | The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without auth... |
| CVE-2021-42232 | CRITICAL | 9.8 | 3.2% | Aug 23, 2022 | TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnera... |
| CVE-2021-3586 | CRITICAL | 9.8 | 0.9% | Aug 22, 2022 | A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify whic... |
| CVE-2021-39085 | CRITICAL | 9.8 | 0.8% | Aug 16, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1... |
| CVE-2021-22289 | CRITICAL | 9.8 | 0.6% | Aug 11, 2022 | Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow... |
| CVE-2021-33643 | CRITICAL | 9.1 | 1.3% | Aug 10, 2022 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo... |
| CVE-2021-41615 | CRITICAL | 9.8 | 1.1% | Aug 8, 2022 | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded... |
| CVE-2021-41556 | CRITICAL | 10 | 2.1% | Jul 28, 2022 | sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca... |
| CVE-2021-22650 | CRITICAL | 9.8 | 1.0% | Jul 28, 2022 | An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWin... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now