2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25745 | HIGH | 8.1 | 1.1% | May 6, 2022 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec... |
| CVE-2021-25268 | HIGH | 8.4 | 0.9% | May 5, 2022 | Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Fire... |
| CVE-2021-25267 | HIGH | 8.4 | 1.1% | May 5, 2022 | Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall old... |
| CVE-2021-44057 | CRITICAL | 9.8 | 0.8% | May 5, 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, th... |
| CVE-2021-44056 | CRITICAL | 9.8 | 0.8% | May 5, 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, th... |
| CVE-2021-44055 | CRITICAL | 9.8 | 1.0% | May 5, 2022 | An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this... |
| CVE-2021-44054 | MEDIUM | 6.1 | 0.5% | May 5, 2022 | An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploite... |
| CVE-2021-44053 | MEDIUM | 6.1 | 0.7% | May 5, 2022 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud.... |
| CVE-2021-44052 | HIGH | 8.1 | 1.4% | May 5, 2022 | An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device ... |
| CVE-2021-44051 | HIGH | 8.8 | 1.6% | May 5, 2022 | A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploite... |
| CVE-2021-43547 | HIGH | 8.2 | 2.4% | May 5, 2022 | TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially... |
| CVE-2021-38693 | MEDIUM | 5.3 | 0.9% | May 5, 2022 | A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Applia... |
| CVE-2021-38487 | CRITICAL | 9.1 | 3.2% | May 5, 2022 | RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker... |
| CVE-2021-38447 | HIGH | 7.5 | 2.0% | May 5, 2022 | OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de... |
| CVE-2021-38445 | CRITICAL | 9.8 | 2.5% | May 5, 2022 | OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associate... |
| CVE-2021-38443 | CRITICAL | 9.8 | 2.1% | May 5, 2022 | Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write ar... |
| CVE-2021-38441 | CRITICAL | 9.8 | 2.0% | May 5, 2022 | Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker t... |
| CVE-2021-38439 | CRITICAL | 9.8 | 2.6% | May 5, 2022 | All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or ... |
| CVE-2021-38435 | CRITICAL | 9.8 | 1.4% | May 5, 2022 | RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocat... |
| CVE-2021-38433 | HIGH | 7.8 | 0.5% | May 5, 2022 | RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 vulnerable to a stack-based buffer overflow, ... |
| CVE-2021-38429 | CRITICAL | 9.1 | 1.4% | May 5, 2022 | OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de... |
| CVE-2021-38427 | HIGH | 7.8 | 0.5% | May 5, 2022 | RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overf... |
| CVE-2021-38425 | CRITICAL | 9.1 | 4.9% | May 5, 2022 | eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially cra... |
| CVE-2021-38423 | CRITICAL | 9.8 | 1.2% | May 5, 2022 | All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buff... |
| CVE-2021-39020 | MEDIUM | 5.3 | 0.5% | May 5, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now