2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42859 | HIGH | 7.5 | 1.0% | May 26, 2022 | A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inco... |
| CVE-2021-42692 | MEDIUM | 6.5 | 0.8% | May 26, 2022 | There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS. |
| CVE-2021-27783 | MEDIUM | 6.5 | 0.3% | May 25, 2022 | User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed. |
| CVE-2021-27779 | CRITICAL | 9.1 | 0.5% | May 25, 2022 | VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on co... |
| CVE-2021-44719 | HIGH | 8.4 | 0.3% | May 25, 2022 | Docker Desktop 4.3.0 has Incorrect Access Control. |
| CVE-2021-35487 | MEDIUM | 6.5 | 1.0% | May 25, 2022 | Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection atta... |
| CVE-2021-32997 | HIGH | 7.5 | 0.3% | May 25, 2022 | The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 Sys... |
| CVE-2021-32989 | MEDIUM | 6.1 | 2.2% | May 25, 2022 | When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns erro... |
| CVE-2021-32966 | HIGH | 7.5 | 0.4% | May 25, 2022 | Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text t... |
| CVE-2021-44974 | MEDIUM | 5.5 | 0.8% | May 25, 2022 | radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol par... |
| CVE-2021-42614 | HIGH | 7.8 | 0.8% | May 24, 2022 | A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or ... |
| CVE-2021-42613 | HIGH | 7.8 | 0.8% | May 24, 2022 | A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly hav... |
| CVE-2021-42612 | HIGH | 7.8 | 0.8% | May 24, 2022 | A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly... |
| CVE-2021-3717 | HIGH | 7.8 | 0.3% | May 24, 2022 | A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may l... |
| CVE-2021-3629 | MEDIUM | 5.9 | 1.2% | May 24, 2022 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potenti... |
| CVE-2021-3597 | MEDIUM | 5.9 | 1.1% | May 24, 2022 | A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting ... |
| CVE-2021-32969 | HIGH | 7.8 | 1.1% | May 24, 2022 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result... |
| CVE-2021-32965 | HIGH | 7.8 | 1.1% | May 24, 2022 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to rem... |
| CVE-2021-32964 | MEDIUM | 5.3 | 0.8% | May 24, 2022 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an a... |
| CVE-2021-32962 | MEDIUM | 6.1 | 0.7% | May 24, 2022 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an atta... |
| CVE-2021-4230 | HIGH | 7.5 | 0.9% | May 24, 2022 | A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /ba... |
| CVE-2021-4229 | HIGH | 8.8 | 1.3% | May 24, 2022 | A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the cryp... |
| CVE-2021-45915 | CRITICAL | 9.8 | 1.5% | May 24, 2022 | In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the ... |
| CVE-2021-45914 | CRITICAL | 9.8 | 1.5% | May 24, 2022 | In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the ... |
| CVE-2021-44975 | MEDIUM | 5.5 | 0.9% | May 24, 2022 | radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now