2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35254 | HIGH | 8.8 | 1.0% | Mar 25, 2022 | SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds ha... |
| CVE-2021-26622 | CRITICAL | 10 | 2.9% | Mar 25, 2022 | An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was dis... |
| CVE-2021-26621 | CRITICAL | 9.8 | 1.6% | Mar 25, 2022 | An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this... |
| CVE-2021-26620 | HIGH | 7.5 | 1.3% | Mar 25, 2022 | An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attack... |
| CVE-2021-22100 | MEDIUM | 5.3 | 0.9% | Mar 25, 2022 | In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker... |
| CVE-2021-20323 | MEDIUM | 6.1 | 37.2% | Mar 25, 2022 | A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. |
| CVE-2021-20290 | MEDIUM | 6.1 | 0.2% | Mar 25, 2022 | An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman cli... |
| CVE-2021-43636 | CRITICAL | 9.8 | 1.0% | Mar 25, 2022 | Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function... |
| CVE-2021-43091 | HIGH | 7.5 | 1.4% | Mar 25, 2022 | An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form. |
| CVE-2021-46426 | MEDIUM | 6.1 | 0.9% | Mar 25, 2022 | phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functiona... |
| CVE-2021-43090 | CRITICAL | 9.8 | 1.9% | Mar 25, 2022 | An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function. |
| CVE-2021-44751 | MEDIUM | 5.3 | 0.6% | Mar 25, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in... |
| CVE-2021-43666 | HIGH | 7.5 | 2.1% | Mar 24, 2022 | A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an... |
| CVE-2021-43085 | — | — | — | Mar 24, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-43084 | CRITICAL | 9.8 | 0.9% | Mar 24, 2022 | An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter. |
| CVE-2021-39491 | MEDIUM | 5.4 | 0.5% | Mar 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan ... |
| CVE-2021-43659 | MEDIUM | 5.4 | 0.5% | Mar 24, 2022 | In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, wh... |
| CVE-2021-43700 | CRITICAL | 9.8 | 1.1% | Mar 24, 2022 | An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8... |
| CVE-2021-31326 | CRITICAL | 9.8 | 2.2% | Mar 24, 2022 | D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parame... |
| CVE-2021-44226 | HIGH | 7.3 | 0.9% | Mar 23, 2022 | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Servi... |
| CVE-2021-28278 | HIGH | 7.8 | 0.9% | Mar 23, 2022 | A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c... |
| CVE-2021-28277 | HIGH | 7.8 | 0.9% | Mar 23, 2022 | A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUn... |
| CVE-2021-28276 | HIGH | 7.5 | 1.1% | Mar 23, 2022 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir ... |
| CVE-2021-28275 | MEDIUM | 5.5 | 0.7% | Mar 23, 2022 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exi... |
| CVE-2021-4219 | MEDIUM | 5.5 | 1.0% | Mar 23, 2022 | A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now