2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36205 | CRITICAL | 9.8 | 1.0% | Apr 15, 2022 | Under certain circumstances the session token is not cleared on logout. |
| CVE-2021-40386 | CRITICAL | 9.8 | 1.8% | Apr 15, 2022 | Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code. |
| CVE-2021-40422 | CRITICAL | 10 | 5.6% | Apr 14, 2022 | An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway S... |
| CVE-2021-40390 | CRITICAL | 9.8 | 2.3% | Apr 14, 2022 | An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specia... |
| CVE-2021-43290 | CRITICAL | 9.8 | 3.2% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma... |
| CVE-2021-42136 | CRITICAL | 9 | 4.5% | Apr 13, 2022 | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows... |
| CVE-2021-22795 | CRITICAL | 9.8 | 3.1% | Apr 13, 2022 | A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists... |
| CVE-2021-22794 | CRITICAL | 9.8 | 2.1% | Apr 13, 2022 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ... |
| CVE-2021-43741 | CRITICAL | 9.8 | 4.5% | Apr 13, 2022 | CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicio... |
| CVE-2021-31805 | CRITICAL | 9.8 | 85.1% | Apr 12, 2022 | The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attribu... |
| CVE-2021-46742 | CRITICAL | 9.1 | 0.7% | Apr 11, 2022 | The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful e... |
| CVE-2021-38125 | CRITICAL | 9.8 | 1.8% | Apr 11, 2022 | Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.0... |
| CVE-2021-37291 | CRITICAL | 9.8 | 8.1% | Apr 11, 2022 | An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id... |
| CVE-2021-32157 | CRITICAL | 9.6 | 4.1% | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. |
| CVE-2021-36288 | CRITICAL | 9.1 | 1.0% | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated... |
| CVE-2021-36287 | CRITICAL | 9.8 | 2.5% | Apr 8, 2022 | Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which ... |
| CVE-2021-43517 | CRITICAL | 9.8 | 1.7% | Apr 8, 2022 | FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port whe... |
| CVE-2021-43474 | CRITICAL | 9.8 | 3.1% | Apr 7, 2022 | An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 functio... |
| CVE-2021-43453 | CRITICAL | 9.8 | 1.2% | Apr 7, 2022 | A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in p... |
| CVE-2021-43421 | CRITICAL | 9.8 | 42.8% | Apr 7, 2022 | A File Upload vulnerability exists in Studio-42 elFinder 2.0.4 to 2.1.59 via connector.minimal.php, which allows a remot... |
| CVE-2021-46419 | CRITICAL | 9.1 | 71.4% | Apr 7, 2022 | An unauthorized file deletion vulnerability in Telesquare TLR-2855KS6 via DELETE method can allow deletion of system fil... |
| CVE-2021-26114 | CRITICAL | 9.8 | 1.5% | Apr 6, 2022 | Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may... |
| CVE-2021-26112 | CRITICAL | 9.8 | 1.6% | Apr 6, 2022 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpret... |
| CVE-2021-41752 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due t... |
| CVE-2021-41751 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now