2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39739 | LOW | 3.3 | 0.1% | Mar 30, 2022 | In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead ... |
| CVE-2021-23851 | HIGH | 7.2 | 1.5% | Mar 30, 2022 | A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer... |
| CVE-2021-23850 | HIGH | 7.2 | 1.5% | Mar 30, 2022 | A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffe... |
| CVE-2021-1033 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe... |
| CVE-2021-1000 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an uns... |
| CVE-2021-41594 | MEDIUM | 6.5 | 0.8% | Mar 30, 2022 | In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by inte... |
| CVE-2021-44082 | HIGH | 8.3 | 2.8% | Mar 29, 2022 | textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthentica... |
| CVE-2021-43118 | CRITICAL | 9.8 | 34.8% | Mar 29, 2022 | A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek V... |
| CVE-2021-42911 | CRITICAL | 9.8 | 3.3% | Mar 29, 2022 | A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor ... |
| CVE-2021-43110 | CRITICAL | 9.8 | 1.5% | Mar 29, 2022 | An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products. |
| CVE-2021-43109 | HIGH | 7.5 | 1.2% | Mar 29, 2022 | An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in pr... |
| CVE-2021-42970 | MEDIUM | 6.1 | 0.7% | Mar 29, 2022 | Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter. |
| CVE-2021-44081 | HIGH | 7.5 | 1.0% | Mar 29, 2022 | A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 character... |
| CVE-2021-43701 | MEDIUM | 6.5 | 3.3% | Mar 29, 2022 | CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/articl... |
| CVE-2021-22572 | MEDIUM | 5.5 | 0.1% | Mar 29, 2022 | On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.... |
| CVE-2021-46743 | CRITICAL | 9.1 | 0.8% | Mar 29, 2022 | In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea... |
| CVE-2021-45866 | MEDIUM | 5.4 | 0.5% | Mar 29, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via ... |
| CVE-2021-45865 | CRITICAL | 9.8 | 1.4% | Mar 29, 2022 | A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functio... |
| CVE-2021-44581 | HIGH | 7.5 | 1.0% | Mar 29, 2022 | An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. |
| CVE-2021-43105 | MEDIUM | 4.3 | 0.6% | Mar 28, 2022 | A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific maliciou... |
| CVE-2021-43103 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote m... |
| CVE-2021-43102 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote ma... |
| CVE-2021-43101 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a... |
| CVE-2021-43100 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote m... |
| CVE-2021-43099 | MEDIUM | 4.9 | 1.1% | Mar 28, 2022 | An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now