2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27762 | CRITICAL | 9.8 | 0.7% | May 6, 2022 | Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web ... |
| CVE-2021-44057 | CRITICAL | 9.8 | 0.8% | May 5, 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, th... |
| CVE-2021-44056 | CRITICAL | 9.8 | 0.8% | May 5, 2022 | An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, th... |
| CVE-2021-44055 | CRITICAL | 9.8 | 1.0% | May 5, 2022 | An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this... |
| CVE-2021-38487 | CRITICAL | 9.1 | 3.2% | May 5, 2022 | RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker... |
| CVE-2021-38445 | CRITICAL | 9.8 | 2.5% | May 5, 2022 | OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associate... |
| CVE-2021-38443 | CRITICAL | 9.8 | 2.1% | May 5, 2022 | Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write ar... |
| CVE-2021-38441 | CRITICAL | 9.8 | 2.0% | May 5, 2022 | Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker t... |
| CVE-2021-38439 | CRITICAL | 9.8 | 2.6% | May 5, 2022 | All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or ... |
| CVE-2021-38435 | CRITICAL | 9.8 | 1.4% | May 5, 2022 | RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocat... |
| CVE-2021-38429 | CRITICAL | 9.1 | 1.4% | May 5, 2022 | OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de... |
| CVE-2021-38425 | CRITICAL | 9.1 | 4.9% | May 5, 2022 | eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially cra... |
| CVE-2021-38423 | CRITICAL | 9.8 | 1.2% | May 5, 2022 | All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buff... |
| CVE-2021-42242 | CRITICAL | 9.8 | 1.9% | May 5, 2022 | A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. |
| CVE-2021-41739 | CRITICAL | 9.8 | 2.7% | May 5, 2022 | A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cy... |
| CVE-2021-42235 | CRITICAL | 9.8 | 0.9% | May 4, 2022 | SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTic... |
| CVE-2021-42185 | CRITICAL | 9.8 | 1.0% | May 4, 2022 | wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function. |
| CVE-2021-43163 | CRITICAL | 9.8 | 2.2% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-27439 | CRITICAL | 9.8 | 1.4% | May 3, 2022 | TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of... |
| CVE-2021-27435 | CRITICAL | 9.8 | 1.6% | May 3, 2022 | ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitr... |
| CVE-2021-27433 | CRITICAL | 9.8 | 1.6% | May 3, 2022 | ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead ... |
| CVE-2021-27431 | CRITICAL | 9.8 | 1.0% | May 3, 2022 | ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalen... |
| CVE-2021-27427 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead ... |
| CVE-2021-27425 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory as... |
| CVE-2021-27421 | CRITICAL | 9.8 | 0.8% | May 3, 2022 | NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now