2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29755 | HIGH | 7.5 | 0.4% | Jul 20, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM... |
| CVE-2021-31858 | MEDIUM | 5.4 | 0.5% | Jul 20, 2022 | DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography se... |
| CVE-2021-46828 | HIGH | 7.5 | 2.1% | Jul 20, 2022 | In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because... |
| CVE-2021-32504 | MEDIUM | 5.3 | 0.5% | Jul 19, 2022 | Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users... |
| CVE-2021-41031 | HIGH | 7.8 | 0.5% | Jul 18, 2022 | A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior an... |
| CVE-2021-38868 | MEDIUM | 6.5 | 0.3% | Jul 18, 2022 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery wh... |
| CVE-2021-29799 | MEDIUM | 6.5 | 0.7% | Jul 18, 2022 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain se... |
| CVE-2021-29790 | MEDIUM | 5.4 | 0.4% | Jul 18, 2022 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vu... |
| CVE-2021-29788 | MEDIUM | 5.4 | 0.4% | Jul 18, 2022 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vu... |
| CVE-2021-22131 | MEDIUM | 5.4 | 0.1% | Jul 18, 2022 | A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet ... |
| CVE-2021-44170 | MEDIUM | 6.7 | 0.2% | Jul 18, 2022 | A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiP... |
| CVE-2021-42755 | MEDIUM | 4.3 | 0.4% | Jul 18, 2022 | An integer overflow / wraparound vulnerability [CWE-190] in FortiSwitch 7.0.2 and below, 6.4.9 and below, 6.2.x, 6.0.x; ... |
| CVE-2021-33656 | MEDIUM | 6.8 | 0.5% | Jul 18, 2022 | When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. |
| CVE-2021-33655 | MEDIUM | 6.7 | 0.3% | Jul 18, 2022 | When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. |
| CVE-2021-44954 | HIGH | 7.8 | 0.3% | Jul 18, 2022 | In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a... |
| CVE-2021-42923 | HIGH | 7.3 | 0.2% | Jul 18, 2022 | ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-Sh... |
| CVE-2021-41419 | CRITICAL | 9.8 | 6.8% | Jul 18, 2022 | QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. |
| CVE-2021-40874 | CRITICAL | 9.8 | 0.9% | Jul 18, 2022 | An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST ... |
| CVE-2021-40150 | HIGH | 7.5 | 3.4% | Jul 17, 2022 | The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp... |
| CVE-2021-46784 | MEDIUM | 6.5 | 3.6% | Jul 17, 2022 | In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Servic... |
| CVE-2021-40149 | MEDIUM | 5.9 | 6.0% | Jul 17, 2022 | The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. ... |
| CVE-2021-24655 | HIGH | 7.5 | 0.8% | Jul 17, 2022 | The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related t... |
| CVE-2021-36711 | CRITICAL | 9.8 | 12.1% | Jul 16, 2022 | WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled. |
| CVE-2021-34538 | HIGH | 7.5 | 1.4% | Jul 16, 2022 | Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved ... |
| CVE-2021-34987 | HIGH | 8.2 | 0.3% | Jul 15, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now