2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39085 | CRITICAL | 9.8 | 0.8% | Aug 16, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1... |
| CVE-2021-39035 | MEDIUM | 5.4 | 0.4% | Aug 16, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1... |
| CVE-2021-30490 | HIGH | 7.8 | 0.3% | Aug 16, 2022 | upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binar... |
| CVE-2021-33236 | — | — | — | Aug 15, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34033. Reason: This candidate is a duplicate of ... |
| CVE-2021-33235 | — | — | — | Aug 15, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34035. Reason: This candidate is a duplicate of ... |
| CVE-2021-29118 | MEDIUM | 5.5 | 0.3% | Aug 12, 2022 | An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) ... |
| CVE-2021-29117 | HIGH | 7.8 | 0.4% | Aug 12, 2022 | A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an un... |
| CVE-2021-29112 | MEDIUM | 5.5 | 0.3% | Aug 12, 2022 | An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) ... |
| CVE-2021-42751 | MEDIUM | 4.8 | 2.3% | Aug 12, 2022 | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat... |
| CVE-2021-42750 | MEDIUM | 4.8 | 2.3% | Aug 12, 2022 | A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrat... |
| CVE-2021-44720 | HIGH | 7.2 | 2.3% | Aug 12, 2022 | In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source... |
| CVE-2021-22289 | CRITICAL | 9.8 | 0.6% | Aug 11, 2022 | Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow... |
| CVE-2021-0975 | MEDIUM | 5.5 | 0.1% | Aug 11, 2022 | In USB Manager, there is a possible way to determine whether an app is installed, without query permissions, due to side... |
| CVE-2021-0735 | MEDIUM | 5.5 | 0.1% | Aug 11, 2022 | In PackageManager, there is a possible way to get information about installed packages ignoring limitations introduced i... |
| CVE-2021-0734 | MEDIUM | 5.5 | 0.1% | Aug 11, 2022 | In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side cha... |
| CVE-2021-46778 | MEDIUM | 5.6 | 0.2% | Aug 10, 2022 | Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenam... |
| CVE-2021-40040 | HIGH | 7.5 | 0.5% | Aug 10, 2022 | Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulner... |
| CVE-2021-40034 | HIGH | 7.5 | 0.5% | Aug 10, 2022 | The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of thi... |
| CVE-2021-40030 | HIGH | 7.5 | 0.4% | Aug 10, 2022 | The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidential... |
| CVE-2021-39696 | HIGH | 7.8 | 0.2% | Aug 10, 2022 | In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation ... |
| CVE-2021-33646 | HIGH | 7.5 | 1.4% | Aug 10, 2022 | The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory ... |
| CVE-2021-33645 | HIGH | 7.5 | 1.4% | Aug 10, 2022 | The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory ... |
| CVE-2021-33644 | HIGH | 8.1 | 1.1% | Aug 10, 2022 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo... |
| CVE-2021-33643 | CRITICAL | 9.1 | 1.3% | Aug 10, 2022 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo... |
| CVE-2021-46304 | HIGH | 7.5 | 0.6% | Aug 10, 2022 | A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WI... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now