2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45935 | MEDIUM | 5.5 | 0.9% | Jan 1, 2022 | Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task... |
| CVE-2021-45934 | MEDIUM | 5.5 | 0.9% | Jan 1, 2022 | wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_HandlePacket an... |
| CVE-2021-45933 | MEDIUM | 5.5 | 0.9% | Jan 1, 2022 | wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecode_Publish (called from MqttClient_DecodePack... |
| CVE-2021-45932 | MEDIUM | 5.5 | 0.9% | Jan 1, 2022 | wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecode_Publish (called from MqttClient_DecodePack... |
| CVE-2021-45931 | MEDIUM | 6.5 | 1.8% | Jan 1, 2022 | HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_inverti... |
| CVE-2021-45930 | MEDIUM | 5.5 | 1.3% | Jan 1, 2022 | Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPain... |
| CVE-2021-45928 | MEDIUM | 5.5 | 0.4% | Jan 1, 2022 | libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFra... |
| CVE-2021-45958 | MEDIUM | 5.5 | 1.6% | Jan 1, 2022 | UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encod... |
| CVE-2021-45950 | MEDIUM | 6.5 | 0.9% | Jan 1, 2022 | LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOC... |
| CVE-2021-45949 | MEDIUM | 5.5 | 1.4% | Jan 1, 2022 | Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_da... |
| CVE-2021-45948 | MEDIUM | 5.5 | 0.9% | Jan 1, 2022 | Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d... |
| CVE-2021-45947 | MEDIUM | 5.5 | 0.7% | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments). |
| CVE-2021-45946 | MEDIUM | 5.5 | 0.7% | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements). |
| CVE-2021-45944 | MEDIUM | 5.5 | 1.4% | Jan 1, 2022 | Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue ... |
| CVE-2021-45929 | MEDIUM | 5.5 | 0.7% | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If). |
| CVE-2021-4193 | MEDIUM | 5.5 | 1.8% | Dec 31, 2021 | vim is vulnerable to Out-of-bounds Read |
| CVE-2021-4183 | MEDIUM | 5.5 | 1.4% | Dec 30, 2021 | Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file |
| CVE-2021-23147 | MEDIUM | 6.8 | 0.4% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor w... |
| CVE-2021-20171 | MEDIUM | 5.5 | 0.2% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's a... |
| CVE-2021-20169 | MEDIUM | 6.8 | 0.2% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communicatio... |
| CVE-2021-20168 | MEDIUM | 6.8 | 0.3% | Dec 30, 2021 | Netgear RAX43 version 1.0.3.96 does not have sufficient protections to the UART interface. A malicious actor with physic... |
| CVE-2021-20164 | MEDIUM | 4.9 | 0.7% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses credentials for the smb functionality of the device. Use... |
| CVE-2021-20163 | MEDIUM | 4.9 | 0.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp u... |
| CVE-2021-20162 | MEDIUM | 4.9 | 0.5% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaint... |
| CVE-2021-20161 | MEDIUM | 6.8 | 0.2% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient protections for the UART functionality. A malicious ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now