2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32953 | CRITICAL | 9.8 | 1.2% | Apr 1, 2022 | An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’... |
| CVE-2021-32949 | HIGH | 7.5 | 1.1% | Apr 1, 2022 | An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path ... |
| CVE-2021-32945 | HIGH | 7.5 | 0.4% | Apr 1, 2022 | An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06. |
| CVE-2021-32937 | HIGH | 7.5 | 1.0% | Apr 1, 2022 | An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in ... |
| CVE-2021-32933 | CRITICAL | 9.8 | 1.2% | Apr 1, 2022 | An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command... |
| CVE-2021-32503 | MEDIUM | 4.9 | 0.8% | Apr 1, 2022 | Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users... |
| CVE-2021-28504 | HIGH | 7.5 | 0.7% | Apr 1, 2022 | On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which m... |
| CVE-2021-27501 | CRITICAL | 9.8 | 0.9% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to res... |
| CVE-2021-27497 | CRITICAL | 9.8 | 0.8% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides suffi... |
| CVE-2021-27493 | MEDIUM | 6.5 | 0.7% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well... |
| CVE-2021-27223 | MEDIUM | 5.5 | 0.2% | Apr 1, 2022 | A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and ... |
| CVE-2021-26624 | HIGH | 8.8 | 2.3% | Apr 1, 2022 | An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due ... |
| CVE-2021-26623 | CRITICAL | 9.8 | 1.1% | Apr 1, 2022 | A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter leng... |
| CVE-2021-23288 | MEDIUM | 4.8 | 0.3% | Apr 1, 2022 | The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacke... |
| CVE-2021-23287 | MEDIUM | 5.4 | 0.4% | Apr 1, 2022 | The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issu... |
| CVE-2021-23247 | CRITICAL | 9.8 | 1.7% | Apr 1, 2022 | A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote att... |
| CVE-2021-22277 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Produc... |
| CVE-2021-20295 | MEDIUM | 6.5 | 0.3% | Apr 1, 2022 | It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-... |
| CVE-2021-20238 | LOW | 3.7 | 0.7% | Apr 1, 2022 | It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accesse... |
| CVE-2021-44135 | CRITICAL | 9.8 | 1.5% | Apr 1, 2022 | pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing. |
| CVE-2021-46443 | — | — | — | Apr 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-35117 | CRITICAL | 9.1 | 0.8% | Apr 1, 2022 | An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Sna... |
| CVE-2021-35115 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon... |
| CVE-2021-35110 | HIGH | 8.8 | 0.2% | Apr 1, 2022 | Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivi... |
| CVE-2021-35106 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Sn... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now