2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38944 | MEDIUM | 6.1 | 0.5% | May 18, 2022 | IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnera... |
| CVE-2021-42704 | HIGH | 7.8 | 1.3% | May 18, 2022 | Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. |
| CVE-2021-42702 | LOW | 3.3 | 0.8% | May 18, 2022 | Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized in... |
| CVE-2021-42700 | LOW | 3.3 | 0.7% | May 18, 2022 | Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized informa... |
| CVE-2021-42852 | HIGH | 8 | 0.8% | May 18, 2022 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authent... |
| CVE-2021-42851 | MEDIUM | 5.3 | 0.5% | May 18, 2022 | A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to c... |
| CVE-2021-42850 | HIGH | 7.8 | 0.2% | May 18, 2022 | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud S... |
| CVE-2021-42849 | MEDIUM | 6.8 | 0.2% | May 18, 2022 | A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow ... |
| CVE-2021-42848 | MEDIUM | 5.3 | 0.7% | May 18, 2022 | An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an u... |
| CVE-2021-3969 | HIGH | 7 | 1.8% | May 18, 2022 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System I... |
| CVE-2021-3956 | MEDIUM | 5.3 | 0.7% | May 18, 2022 | A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Contro... |
| CVE-2021-3922 | HIGH | 7 | 1.8% | May 18, 2022 | A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,... |
| CVE-2021-27548 | MEDIUM | 5.5 | 0.7% | May 18, 2022 | There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03. |
| CVE-2021-41946 | MEDIUM | 5.4 | 2.4% | May 18, 2022 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access... |
| CVE-2021-35249 | MEDIUM | 4.3 | 0.6% | May 17, 2022 | This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user dat... |
| CVE-2021-38872 | HIGH | 7.5 | 1.4% | May 17, 2022 | IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a re... |
| CVE-2021-29726 | MEDIUM | 5.3 | 0.8% | May 17, 2022 | IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a cert... |
| CVE-2021-42644 | MEDIUM | 6.5 | 0.9% | May 17, 2022 | cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file informa... |
| CVE-2021-42643 | HIGH | 8.8 | 1.6% | May 17, 2022 | cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script f... |
| CVE-2021-42943 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrar... |
| CVE-2021-33025 | HIGH | 7.8 | 0.3% | May 16, 2022 | xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges. |
| CVE-2021-33021 | MEDIUM | 6.1 | 0.7% | May 16, 2022 | xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisa... |
| CVE-2021-33001 | MEDIUM | 6.1 | 0.7% | May 16, 2022 | xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisv... |
| CVE-2021-27446 | CRITICAL | 9.8 | 2.6% | May 16, 2022 | The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to exec... |
| CVE-2021-27444 | CRITICAL | 9.8 | 1.1% | May 16, 2022 | The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attac... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now