2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32953CRITICAL9.8An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’...
CVE-2021-32949HIGH7.5An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path ...
CVE-2021-32945HIGH7.5An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.
CVE-2021-32937HIGH7.5An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in ...
CVE-2021-32933CRITICAL9.8An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command...
CVE-2021-32503MEDIUM4.9Unauthenticated users can access sensitive web URLs through GET request, which should be restricted to maintenance users...
CVE-2021-28504HIGH7.5On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which m...
CVE-2021-27501CRITICAL9.8Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to res...
CVE-2021-27497CRITICAL9.8Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides suffi...
CVE-2021-27493MEDIUM6.5Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well...
CVE-2021-27223MEDIUM5.5A denial-of-service issue existed in one of modules that was incorporated in Kaspersky Anti-Virus products for home and ...
CVE-2021-26624HIGH8.8An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due ...
CVE-2021-26623CRITICAL9.8A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter leng...
CVE-2021-23288MEDIUM4.8The vulnerability exists due to insufficient validation of input from certain resources by the IPP software. The attacke...
CVE-2021-23287MEDIUM5.4The vulnerability exists due to insufficient validation of input of certain resources within the IPM software. This issu...
CVE-2021-23247CRITICAL9.8A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote att...
CVE-2021-22277HIGH7.5Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Produc...
CVE-2021-20295MEDIUM6.5It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-...
CVE-2021-20238LOW3.7It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accesse...
CVE-2021-44135CRITICAL9.8pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.
CVE-2021-46443Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-35117CRITICAL9.1An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Sna...
CVE-2021-35115HIGH7.8Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon...
CVE-2021-35110HIGH8.8Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivi...
CVE-2021-35106HIGH7.8Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Sn...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now