2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27419 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memor... |
| CVE-2021-27417 | CRITICAL | 9.8 | 0.5% | May 3, 2022 | eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implem... |
| CVE-2021-22680 | CRITICAL | 9.8 | 1.4% | May 3, 2022 | NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. T... |
| CVE-2021-3643 | CRITICAL | 9.1 | 1.4% | May 2, 2022 | A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw a... |
| CVE-2021-42001 | CRITICAL | 9.9 | 0.5% | Apr 30, 2022 | PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposu... |
| CVE-2021-43938 | CRITICAL | 9.8 | 1.0% | Apr 29, 2022 | Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server witho... |
| CVE-2021-44596 | CRITICAL | 9.8 | 22.7% | Apr 29, 2022 | Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an ... |
| CVE-2021-43934 | CRITICAL | 9.8 | 1.1% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling... |
| CVE-2021-41945 | CRITICAL | 9.1 | 2.2% | Apr 28, 2022 | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions usi... |
| CVE-2021-41921 | CRITICAL | 9.8 | 1.6% | Apr 28, 2022 | novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks a... |
| CVE-2021-38869 | CRITICAL | 9.8 | 0.8% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle t... |
| CVE-2021-34601 | CRITICAL | 9.8 | 1.0% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC61... |
| CVE-2021-46424 | CRITICAL | 9.1 | 36.8% | Apr 27, 2022 | Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to de... |
| CVE-2021-46422 | CRITICAL | 9.8 | 94.8% | Apr 27, 2022 | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute... |
| CVE-2021-46442 | CRITICAL | 9.8 | 54.6% | Apr 27, 2022 | In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", a... |
| CVE-2021-45840 | CRITICAL | 9.8 | 3.9% | Apr 25, 2022 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send... |
| CVE-2021-45837 | CRITICAL | 9.8 | 15.9% | Apr 25, 2022 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send... |
| CVE-2021-3897 | CRITICAL | 9.8 | 1.2% | Apr 22, 2022 | An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) ... |
| CVE-2021-3849 | CRITICAL | 9.8 | 1.2% | Apr 22, 2022 | An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) an... |
| CVE-2021-36203 | CRITICAL | 9.1 | 0.8% | Apr 22, 2022 | The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially craf... |
| CVE-2021-43481 | CRITICAL | 9.8 | 5.5% | Apr 20, 2022 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag... |
| CVE-2021-44496 | CRITICAL | 9.8 | 1.9% | Apr 15, 2022 | An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacke... |
| CVE-2021-44488 | CRITICAL | 9.1 | 1.0% | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can control the size and i... |
| CVE-2021-44486 | CRITICAL | 9.8 | 1.8% | Apr 15, 2022 | An issue was discovered in YottaDB through r1.32 and V7.0-000. Using crafted input, attackers can manipulate the value o... |
| CVE-2021-42230 | CRITICAL | 9.8 | 5.9% | Apr 15, 2022 | Seowon 130-SLC router all versions as of 2021-09-15 is vulnerable to Remote Code Execution via the queriesCnt parameter. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now