2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43581 | HIGH | 8.8 | 1.2% | Nov 22, 2021 | An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. Th... |
| CVE-2021-43557 | HIGH | 7.5 | 14.6% | Nov 22, 2021 | The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full... |
| CVE-2021-38146 | HIGH | 7.5 | 11.7% | Nov 22, 2021 | The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary ... |
| CVE-2021-28710 | HIGH | 8.8 | 0.3% | Nov 21, 2021 | certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structure... |
| CVE-2021-23217 | HIGH | 7.5 | 0.3% | Nov 20, 2021 | NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with eleva... |
| CVE-2021-23201 | HIGH | 7.5 | 0.3% | Nov 20, 2021 | NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevat... |
| CVE-2021-36321 | HIGH | 7.5 | 1.2% | Nov 20, 2021 | Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote... |
| CVE-2021-36307 | HIGH | 8.8 | 0.9% | Nov 20, 2021 | Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability... |
| CVE-2021-34358 | HIGH | 8.8 | 0.4% | Nov 20, 2021 | We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and la... |
| CVE-2021-21898 | HIGH | 8.8 | 2.5% | Nov 19, 2021 | A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-... |
| CVE-2021-44038 | HIGH | 7.8 | 0.8% | Nov 19, 2021 | An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (w... |
| CVE-2021-43555 | HIGH | 7.8 | 38.0% | Nov 19, 2021 | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may ... |
| CVE-2021-42254 | HIGH | 7.8 | 0.3% | Nov 19, 2021 | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions... |
| CVE-2021-22970 | HIGH | 7.5 | 1.4% | Nov 19, 2021 | Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system... |
| CVE-2021-22968 | HIGH | 7.2 | 3.1% | Nov 19, 2021 | A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Co... |
| CVE-2021-22967 | HIGH | 7.5 | 1.1% | Nov 19, 2021 | In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowe... |
| CVE-2021-22966 | HIGH | 8.8 | 0.9% | Nov 19, 2021 | Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "... |
| CVE-2021-22965 | HIGH | 7.5 | 2.1% | Nov 19, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial ... |
| CVE-2021-22951 | HIGH | 7.5 | 1.1% | Nov 19, 2021 | Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) p... |
| CVE-2021-21900 | HIGH | 8.8 | 2.5% | Nov 19, 2021 | A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f... |
| CVE-2021-21899 | HIGH | 8.8 | 2.7% | Nov 19, 2021 | A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2... |
| CVE-2021-41569 | HIGH | 7.5 | 7.8% | Nov 19, 2021 | SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app... |
| CVE-2021-44037 | HIGH | 7.5 | 0.8% | Nov 19, 2021 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning. |
| CVE-2021-44036 | HIGH | 8.8 | 0.4% | Nov 19, 2021 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import. |
| CVE-2021-3962 | HIGH | 7.8 | 5.8% | Nov 19, 2021 | A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert proce... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now