2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44138 | HIGH | 7.5 | 14.1% | Apr 4, 2022 | There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remo... |
| CVE-2021-36776 | HIGH | 8.8 | 1.1% | Apr 4, 2022 | A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue ... |
| CVE-2021-36775 | HIGH | 8.8 | 0.9% | Apr 4, 2022 | a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. T... |
| CVE-2021-33616 | MEDIUM | 5.4 | 0.7% | Apr 4, 2022 | RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS. |
| CVE-2021-30066 | MEDIUM | 6.8 | 0.2% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-30065 | HIGH | 7.5 | 0.8% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-30064 | CRITICAL | 9.8 | 0.9% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-30063 | HIGH | 7.5 | 1.0% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafte... |
| CVE-2021-30062 | HIGH | 7.5 | 0.8% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafte... |
| CVE-2021-30061 | MEDIUM | 6.8 | 0.4% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon ... |
| CVE-2021-3847 | HIGH | 7.8 | 0.5% | Apr 1, 2022 | An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsyste... |
| CVE-2021-3461 | HIGH | 7.1 | 0.3% | Apr 1, 2022 | A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SA... |
| CVE-2021-39908 | HIGH | 7.5 | 1.2% | Apr 1, 2022 | In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and al... |
| CVE-2021-33657 | HIGH | 8.8 | 2.0% | Apr 1, 2022 | There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By craf... |
| CVE-2021-33024 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure met... |
| CVE-2021-33022 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communicati... |
| CVE-2021-33020 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which dimini... |
| CVE-2021-33018 | HIGH | 7.5 | 0.5% | Apr 1, 2022 | The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary r... |
| CVE-2021-32976 | CRITICAL | 9.8 | 2.6% | Apr 1, 2022 | Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may a... |
| CVE-2021-32974 | CRITICAL | 9.8 | 2.6% | Apr 1, 2022 | Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier m... |
| CVE-2021-32970 | HIGH | 7.5 | 1.6% | Apr 1, 2022 | Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 ... |
| CVE-2021-32968 | HIGH | 7.5 | 1.6% | Apr 1, 2022 | Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may al... |
| CVE-2021-32961 | HIGH | 7.5 | 1.2% | Apr 1, 2022 | A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting ... |
| CVE-2021-32960 | HIGH | 8.8 | 2.3% | Apr 1, 2022 | Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed con... |
| CVE-2021-32957 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now