2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20047 | HIGH | 7.8 | 0.9% | Dec 8, 2021 | SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerabili... |
| CVE-2021-20044 | HIGH | 8.8 | 40.1% | Dec 8, 2021 | A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker ... |
| CVE-2021-20043 | HIGH | 8.8 | 23.3% | Dec 8, 2021 | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacke... |
| CVE-2021-20041 | HIGH | 7.5 | 6.8% | Dec 8, 2021 | An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 ... |
| CVE-2021-20040 | HIGH | 7.5 | 25.8% | Dec 8, 2021 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload ... |
| CVE-2021-20039 | HIGH | 8.8 | 78.1% | Dec 8, 2021 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo... |
| CVE-2021-44725 | HIGH | 7.5 | 1.5% | Dec 8, 2021 | KNIME Server before 4.13.4 allows directory traversal in a request for a client profile. |
| CVE-2021-41311 | HIGH | 7.5 | 0.8% | Dec 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that ... |
| CVE-2021-44420 | HIGH | 7.3 | 2.3% | Dec 8, 2021 | In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines cou... |
| CVE-2021-43963 | HIGH | 8.1 | 0.5% | Dec 7, 2021 | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write dat... |
| CVE-2021-42717 | HIGH | 7.5 | 3.2% | Dec 7, 2021 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thou... |
| CVE-2021-40578 | HIGH | 7.2 | 1.5% | Dec 7, 2021 | Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in P... |
| CVE-2021-44149 | HIGH | 7.8 | 0.3% | Dec 7, 2021 | An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL So... |
| CVE-2021-42688 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x2200... |
| CVE-2021-42687 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B... |
| CVE-2021-42686 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Acco... |
| CVE-2021-42685 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 . The IOCTL Handler 0x22005B in... |
| CVE-2021-42683 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B... |
| CVE-2021-42682 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B all... |
| CVE-2021-42681 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | A Buffer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105. The IOCTL Handler 0x22001B allow... |
| CVE-2021-36133 | HIGH | 7.1 | 0.3% | Dec 7, 2021 | The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in Tr... |
| CVE-2021-34543 | HIGH | 7.5 | 2.9% | Dec 7, 2021 | The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remot... |
| CVE-2021-28680 | HIGH | 8.1 | 1.2% | Dec 7, 2021 | The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses ... |
| CVE-2021-43638 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent be... |
| CVE-2021-43637 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now