2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37150 | HIGH | 7.5 | 1.7% | Aug 10, 2022 | Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure ... |
| CVE-2021-41615 | CRITICAL | 9.8 | 1.1% | Aug 8, 2022 | websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded... |
| CVE-2021-28511 | MEDIUM | 6.5 | 0.5% | Aug 5, 2022 | This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impac... |
| CVE-2021-46681 | MEDIUM | 6.1 | 0.3% | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu... |
| CVE-2021-46680 | MEDIUM | 6.1 | 0.3% | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu... |
| CVE-2021-46679 | MEDIUM | 6.1 | 0.3% | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu... |
| CVE-2021-46678 | MEDIUM | 6.1 | 0.3% | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu... |
| CVE-2021-46677 | MEDIUM | 6.1 | 0.3% | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu... |
| CVE-2021-46676 | MEDIUM | 6.1 | 0.3% | Aug 5, 2022 | A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code execu... |
| CVE-2021-36861 | MEDIUM | 4.3 | 0.3% | Aug 5, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Rich Reviews by Starfish plugin <= 1.9.14 at WordPress allows an atta... |
| CVE-2021-27798 | MEDIUM | 5.5 | 0.2% | Aug 5, 2022 | A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory ... |
| CVE-2021-32771 | HIGH | 8.1 | 1.0% | Aug 4, 2022 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to ca... |
| CVE-2021-43179 | — | — | — | Aug 3, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2021-43178 | — | — | — | Aug 3, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2021-23385 | MEDIUM | 6.1 | 0.9% | Aug 2, 2022 | This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect... |
| CVE-2021-27785 | MEDIUM | 5 | 0.2% | Jul 30, 2022 | HCL Commerce's Remote Store server could allow a local attacker to obtain sensitive personal information. The vulnerabil... |
| CVE-2021-3601 | — | — | — | Jul 29, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Op... |
| CVE-2021-39088 | HIGH | 7.8 | 0.2% | Jul 28, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unkno... |
| CVE-2021-41556 | CRITICAL | 10 | 2.1% | Jul 28, 2022 | sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca... |
| CVE-2021-22650 | CRITICAL | 9.8 | 1.0% | Jul 28, 2022 | An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWin... |
| CVE-2021-22648 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. |
| CVE-2021-22646 | CRITICAL | 9.8 | 1.1% | Jul 28, 2022 | The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TB... |
| CVE-2021-22644 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. |
| CVE-2021-22642 | HIGH | 7.5 | 0.7% | Jul 28, 2022 | An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. |
| CVE-2021-22640 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now