2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27419 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memor... |
| CVE-2021-27417 | CRITICAL | 9.8 | 0.5% | May 3, 2022 | eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implem... |
| CVE-2021-27411 | MEDIUM | 6.5 | 0.8% | May 3, 2022 | Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCr... |
| CVE-2021-22680 | CRITICAL | 9.8 | 1.4% | May 3, 2022 | NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. T... |
| CVE-2021-29854 | HIGH | 7.2 | 1.0% | May 3, 2022 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of... |
| CVE-2021-46440 | HIGH | 7.5 | 2.2% | May 3, 2022 | Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.... |
| CVE-2021-22573 | HIGH | 7.3 | 0.3% | May 3, 2022 | The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sur... |
| CVE-2021-22556 | HIGH | 7.8 | 0.2% | May 3, 2022 | The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache i... |
| CVE-2021-39390 | MEDIUM | 5.4 | 0.6% | May 3, 2022 | Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter. |
| CVE-2021-42165 | HIGH | 8.8 | 13.1% | May 3, 2022 | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing c... |
| CVE-2021-42218 | HIGH | 7.5 | 1.0% | May 3, 2022 | OMPL v1.5.2 contains a memory leak in VFRRT.cpp |
| CVE-2021-41959 | HIGH | 7.5 | 1.1% | May 3, 2022 | JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/... |
| CVE-2021-4138 | MEDIUM | 5.3 | 0.8% | May 2, 2022 | Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified ho... |
| CVE-2021-42532 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42531 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42530 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42529 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42528 | MEDIUM | 5.5 | 1.8% | May 2, 2022 | XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially craft... |
| CVE-2021-41810 | MEDIUM | 4.8 | 0.7% | May 2, 2022 | Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Ad... |
| CVE-2021-36844 | MEDIUM | 4.8 | 0.5% | May 2, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on W... |
| CVE-2021-3750 | HIGH | 8.2 | 0.5% | May 2, 2022 | A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointe... |
| CVE-2021-3643 | CRITICAL | 9.1 | 1.4% | May 2, 2022 | A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw a... |
| CVE-2021-29859 | MEDIUM | 6.8 | 0.3% | May 2, 2022 | IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0... |
| CVE-2021-25102 | MEDIUM | 4.7 | 0.7% | May 2, 2022 | The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect... |
| CVE-2021-25086 | MEDIUM | 6.1 | 1.3% | May 2, 2022 | The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now