2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42577 | HIGH | 7.5 | 0.9% | Mar 11, 2022 | An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client ... |
| CVE-2021-42262 | MEDIUM | 6.5 | 0.8% | Mar 11, 2022 | An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the O... |
| CVE-2021-41850 | HIGH | 7.8 | 0.4% | Mar 11, 2022 | An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroa... |
| CVE-2021-41849 | MEDIUM | 5.5 | 0.2% | Mar 11, 2022 | An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Inform... |
| CVE-2021-41848 | HIGH | 7.8 | 0.4% | Mar 11, 2022 | An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-... |
| CVE-2021-44667 | MEDIUM | 6.1 | 0.8% | Mar 11, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo param... |
| CVE-2021-33658 | HIGH | 7.8 | 0.2% | Mar 11, 2022 | atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate... |
| CVE-2021-33150 | MEDIUM | 6.8 | 0.3% | Mar 11, 2022 | Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an un... |
| CVE-2021-32478 | MEDIUM | 6.1 | 1.2% | Mar 11, 2022 | The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect ... |
| CVE-2021-32477 | MEDIUM | 4.3 | 0.7% | Mar 11, 2022 | The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with ... |
| CVE-2021-32476 | HIGH | 7.5 | 1.0% | Mar 11, 2022 | A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodl... |
| CVE-2021-32475 | MEDIUM | 5.4 | 0.6% | Mar 11, 2022 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10... |
| CVE-2021-32474 | HIGH | 7.2 | 0.9% | Mar 11, 2022 | An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer hos... |
| CVE-2021-32473 | MEDIUM | 5.3 | 1.0% | Mar 11, 2022 | It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.1... |
| CVE-2021-32472 | MEDIUM | 4.3 | 0.7% | Mar 11, 2022 | Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle ve... |
| CVE-2021-32009 | MEDIUM | 6.1 | 0.5% | Mar 11, 2022 | Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject java... |
| CVE-2021-27416 | MEDIUM | 5.4 | 0.6% | Mar 11, 2022 | An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versio... |
| CVE-2021-27414 | MEDIUM | 6.1 | 0.6% | Mar 11, 2022 | An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to an... |
| CVE-2021-26401 | MEDIUM | 5.6 | 0.3% | Mar 11, 2022 | LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. |
| CVE-2021-26341 | MEDIUM | 6.5 | 0.3% | Mar 11, 2022 | Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage... |
| CVE-2021-23246 | HIGH | 7.5 | 0.9% | Mar 11, 2022 | In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user i... |
| CVE-2021-44620 | CRITICAL | 9.8 | 2.3% | Mar 11, 2022 | A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime para... |
| CVE-2021-44618 | CRITICAL | 9.8 | 1.3% | Mar 11, 2022 | A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php... |
| CVE-2021-46708 | MEDIUM | 6.1 | 1.4% | Mar 11, 2022 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the ... |
| CVE-2021-44597 | — | — | — | Mar 10, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43857. Reason: This candidate is a reservation d... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now