2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22648 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file. |
| CVE-2021-22646 | CRITICAL | 9.8 | 1.1% | Jul 28, 2022 | The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TB... |
| CVE-2021-22644 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key. |
| CVE-2021-22640 | CRITICAL | 9.8 | 0.7% | Jul 28, 2022 | An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks. |
| CVE-2021-23451 | CRITICAL | 9.8 | 0.7% | Jul 25, 2022 | The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-ti... |
| CVE-2021-23397 | CRITICAL | 9.8 | 0.7% | Jul 25, 2022 | All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer... |
| CVE-2021-23373 | CRITICAL | 9.8 | 1.0% | Jul 25, 2022 | All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality. |
| CVE-2021-41419 | CRITICAL | 9.8 | 6.8% | Jul 18, 2022 | QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. |
| CVE-2021-40874 | CRITICAL | 9.8 | 0.9% | Jul 18, 2022 | An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST ... |
| CVE-2021-36711 | CRITICAL | 9.8 | 12.1% | Jul 16, 2022 | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. |
| CVE-2021-44222 | CRITICAL | 9.1 | 1.1% | Jul 12, 2022 | A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service o... |
| CVE-2021-35283 | CRITICAL | 9.8 | 0.9% | Jul 7, 2022 | SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via... |
| CVE-2021-29281 | CRITICAL | 9.8 | 1.9% | Jul 7, 2022 | File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik ... |
| CVE-2021-46825 | CRITICAL | 9.1 | 1.4% | Jul 7, 2022 | Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauth... |
| CVE-2021-43702 | CRITICAL | 9 | 0.8% | Jul 5, 2022 | ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitiz... |
| CVE-2021-32428 | CRITICAL | 9.8 | 1.0% | Jul 1, 2022 | SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books... |
| CVE-2021-37778 | CRITICAL | 9.8 | 1.3% | Jun 30, 2022 | There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code ... |
| CVE-2021-41506 | CRITICAL | 9.8 | 1.8% | Jun 30, 2022 | Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351... |
| CVE-2021-40663 | CRITICAL | 9.8 | 1.4% | Jun 30, 2022 | deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes... |
| CVE-2021-40643 | CRITICAL | 9.8 | 2.2% | Jun 30, 2022 | EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the... |
| CVE-2021-40597 | CRITICAL | 9.8 | 1.5% | Jun 29, 2022 | The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password. |
| CVE-2021-39409 | CRITICAL | 9.8 | 2.7% | Jun 24, 2022 | A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without n... |
| CVE-2021-38945 | CRITICAL | 9.8 | 1.6% | Jun 24, 2022 | IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by impro... |
| CVE-2021-40954 | CRITICAL | 9.8 | 1.6% | Jun 23, 2022 | Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary cod... |
| CVE-2021-26638 | CRITICAL | 9.8 | 3.4% | Jun 23, 2022 | Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and inform... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now