2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45915 | CRITICAL | 9.8 | 1.5% | May 24, 2022 | In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the ... |
| CVE-2021-45914 | CRITICAL | 9.8 | 1.5% | May 24, 2022 | In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the ... |
| CVE-2021-42654 | CRITICAL | 9.8 | 1.6% | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be use... |
| CVE-2021-32941 | CRITICAL | 9.8 | 13.3% | May 23, 2022 | Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based... |
| CVE-2021-32935 | CRITICAL | 9.8 | 1.7% | May 23, 2022 | The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which ... |
| CVE-2021-34111 | CRITICAL | 9.8 | 2.5% | May 20, 2022 | Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.ph... |
| CVE-2021-37413 | CRITICAL | 9.8 | 1.8% | May 19, 2022 | GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated... |
| CVE-2021-26630 | CRITICAL | 9.8 | 0.7% | May 19, 2022 | Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbi... |
| CVE-2021-27446 | CRITICAL | 9.8 | 2.6% | May 16, 2022 | The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to exec... |
| CVE-2021-27444 | CRITICAL | 9.8 | 1.1% | May 16, 2022 | The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attac... |
| CVE-2021-33318 | CRITICAL | 9.8 | 1.9% | May 16, 2022 | An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below... |
| CVE-2021-42897 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[... |
| CVE-2021-46786 | CRITICAL | 9.8 | 0.7% | May 13, 2022 | The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation... |
| CVE-2021-42967 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus a... |
| CVE-2021-42863 | CRITICAL | 9.8 | 1.6% | May 12, 2022 | A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to con... |
| CVE-2021-42646 | CRITICAL | 9.1 | 3.7% | May 11, 2022 | XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in... |
| CVE-2021-34085 | CRITICAL | 9.8 | 1.7% | May 11, 2022 | Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows rem... |
| CVE-2021-33316 | CRITICAL | 9.8 | 1.0% | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This... |
| CVE-2021-33315 | CRITICAL | 9.8 | 1.0% | May 11, 2022 | The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from an integer underflow vulnerability. This... |
| CVE-2021-38969 | CRITICAL | 9.8 | 0.7% | May 11, 2022 | IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access due to the reuse of suppo... |
| CVE-2021-43094 | CRITICAL | 9.8 | 1.2% | May 10, 2022 | An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone... |
| CVE-2021-42645 | CRITICAL | 10 | 4.2% | May 10, 2022 | CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker... |
| CVE-2021-42581 | CRITICAL | 9.1 | 1.3% | May 10, 2022 | Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or av... |
| CVE-2021-23792 | CRITICAL | 9.8 | 1.0% | May 6, 2022 | The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injectio... |
| CVE-2021-23592 | CRITICAL | 9.8 | 1.6% | May 6, 2022 | The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unseria... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now