2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27424 | MEDIUM | 5.3 | 0.8% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made ... |
| CVE-2021-27422 | HIGH | 7.5 | 0.6% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sens... |
| CVE-2021-27420 | MEDIUM | 5.3 | 1.0% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs... |
| CVE-2021-27418 | MEDIUM | 6.1 | 0.6% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly... |
| CVE-2021-38772 | HIGH | 7.5 | 1.2% | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBi... |
| CVE-2021-38278 | CRITICAL | 9.8 | 1.4% | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentCont... |
| CVE-2021-46064 | HIGH | 7.8 | 1.4% | Mar 23, 2022 | IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). T... |
| CVE-2021-44139 | HIGH | 7.5 | 6.5% | Mar 23, 2022 | Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). |
| CVE-2021-43737 | MEDIUM | 6.5 | 0.4% | Mar 23, 2022 | An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account... |
| CVE-2021-43738 | HIGH | 8.8 | 0.5% | Mar 23, 2022 | An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrat... |
| CVE-2021-43736 | CRITICAL | 9.8 | 2.3% | Mar 23, 2022 | CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule |
| CVE-2021-43735 | CRITICAL | 9.8 | 1.2% | Mar 23, 2022 | CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. |
| CVE-2021-44759 | HIGH | 8.1 | 1.5% | Mar 23, 2022 | Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a m... |
| CVE-2021-44040 | HIGH | 7.5 | 1.9% | Mar 23, 2022 | Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send inva... |
| CVE-2021-25220 | MEDIUM | 6.8 | 3.3% | Mar 23, 2022 | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.... |
| CVE-2021-45757 | HIGH | 7.5 | 1.8% | Mar 23, 2022 | ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (Do... |
| CVE-2021-45756 | CRITICAL | 9.8 | 1.7% | Mar 23, 2022 | Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.... |
| CVE-2021-33961 | MEDIUM | 6.1 | 0.7% | Mar 22, 2022 | A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter. |
| CVE-2021-41736 | CRITICAL | 9.8 | 1.4% | Mar 22, 2022 | Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp. |
| CVE-2021-43650 | CRITICAL | 9.8 | 6.2% | Mar 22, 2022 | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. |
| CVE-2021-45810 | HIGH | 7.5 | 0.8% | Mar 22, 2022 | GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService thro... |
| CVE-2021-45809 | CRITICAL | 9.8 | 1.6% | Mar 22, 2022 | GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GU... |
| CVE-2021-40662 | HIGH | 8.8 | 1.1% | Mar 21, 2022 | A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim host... |
| CVE-2021-38745 | MEDIUM | 6.8 | 0.8% | Mar 21, 2022 | Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execu... |
| CVE-2021-46390 | MEDIUM | 6.8 | 0.5% | Mar 21, 2022 | An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now