2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45470 | HIGH | 7.5 | 1.9% | Dec 23, 2021 | lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular ex... |
| CVE-2021-3621 | HIGH | 8.8 | 2.5% | Dec 23, 2021 | A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach... |
| CVE-2021-44542 | HIGH | 7.5 | 1.2% | Dec 23, 2021 | A memory leak vulnerability was found in Privoxy when handling errors. |
| CVE-2021-44541 | HIGH | 7.5 | 1.4% | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory whe... |
| CVE-2021-44540 | HIGH | 7.5 | 1.3% | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec ... |
| CVE-2021-43989 | HIGH | 7.5 | 0.7% | Dec 23, 2021 | mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously ... |
| CVE-2021-3584 | HIGH | 7.2 | 3.9% | Dec 23, 2021 | A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendm... |
| CVE-2021-35243 | HIGH | 7.5 | 0.9% | Dec 23, 2021 | The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to exe... |
| CVE-2021-20318 | HIGH | 7.2 | 1.7% | Dec 23, 2021 | The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use th... |
| CVE-2021-45469 | HIGH | 7.8 | 0.5% | Dec 23, 2021 | In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when ... |
| CVE-2021-40161 | HIGH | 7.8 | 1.4% | Dec 23, 2021 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earli... |
| CVE-2021-40160 | HIGH | 7.8 | 1.5% | Dec 23, 2021 | PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF ... |
| CVE-2021-4118 | HIGH | 7.8 | 1.0% | Dec 23, 2021 | pytorch-lightning is vulnerable to Deserialization of Untrusted Data |
| CVE-2021-43854 | HIGH | 7.5 | 2.7% | Dec 23, 2021 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2021-23175 | HIGH | 8.2 | 0.4% | Dec 23, 2021 | NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply indi... |
| CVE-2021-44600 | HIGH | 7.5 | 1.3% | Dec 23, 2021 | The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injectio... |
| CVE-2021-44599 | HIGH | 7.5 | 1.2% | Dec 23, 2021 | The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. ... |
| CVE-2021-44273 | HIGH | 7.4 | 1.0% | Dec 23, 2021 | e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mod... |
| CVE-2021-4144 | HIGH | 8.8 | 1.9% | Dec 23, 2021 | TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection. |
| CVE-2021-45463 | HIGH | 7.8 | 1.4% | Dec 23, 2021 | load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or ... |
| CVE-2021-45462 | HIGH | 7.5 | 4.4% | Dec 23, 2021 | In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF. |
| CVE-2021-20050 | HIGH | 7.5 | 0.9% | Dec 23, 2021 | An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessi... |
| CVE-2021-20049 | HIGH | 7.5 | 1.3% | Dec 23, 2021 | A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 usern... |
| CVE-2021-4079 | HIGH | 8.8 | 0.8% | Dec 23, 2021 | Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit he... |
| CVE-2021-4078 | HIGH | 8.8 | 1.0% | Dec 23, 2021 | Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corrup... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now