2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44749 | CRITICAL | 9.6 | 0.8% | Mar 6, 2022 | A vulnerability affecting F-Secure SAFE browser protection was discovered improper URL handling can be triggered to caus... |
| CVE-2021-44748 | MEDIUM | 6.1 | 0.5% | Mar 6, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerab... |
| CVE-2021-46704 | CRITICAL | 9.8 | 21.9% | Mar 6, 2022 | In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping ... |
| CVE-2021-46703 | CRITICAL | 9.8 | 1.8% | Mar 6, 2022 | In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .N... |
| CVE-2021-46384 | CRITICAL | 9.8 | 2.1% | Mar 4, 2022 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The at... |
| CVE-2021-46353 | MEDIUM | 5.3 | 2.1% | Mar 4, 2022 | An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacke... |
| CVE-2021-44827 | HIGH | 8.8 | 54.0% | Mar 4, 2022 | There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devi... |
| CVE-2021-40846 | HIGH | 7.5 | 0.7% | Mar 4, 2022 | An issue was discovered in Rhinode Trading Paints through 2.0.36. TP Updater.exe uses cleartext HTTP to check, and reque... |
| CVE-2021-32008 | HIGH | 8.7 | 1.0% | Mar 4, 2022 | This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname ... |
| CVE-2021-27756 | HIGH | 7.5 | 0.5% | Mar 4, 2022 | "TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled... |
| CVE-2021-43590 | MEDIUM | 6 | 0.1% | Mar 4, 2022 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password st... |
| CVE-2021-3737 | HIGH | 7.5 | 11.6% | Mar 4, 2022 | A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote att... |
| CVE-2021-3656 | HIGH | 8.8 | 0.7% | Mar 4, 2022 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC... |
| CVE-2021-27757 | HIGH | 7.5 | 0.6% | Mar 4, 2022 | " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might... |
| CVE-2021-3575 | HIGH | 7.8 | 1.5% | Mar 4, 2022 | A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k... |
| CVE-2021-3428 | MEDIUM | 5.5 | 0.3% | Mar 4, 2022 | A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a craf... |
| CVE-2021-20319 | HIGH | 7.8 | 0.5% | Mar 4, 2022 | An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation im... |
| CVE-2021-20303 | MEDIUM | 6.1 | 0.8% | Mar 4, 2022 | A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted fil... |
| CVE-2021-20302 | MEDIUM | 5.5 | 0.9% | Mar 4, 2022 | A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single... |
| CVE-2021-20300 | MEDIUM | 5.5 | 0.9% | Mar 4, 2022 | A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who... |
| CVE-2021-46382 | MEDIUM | 6.1 | 0.7% | Mar 4, 2022 | Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session h... |
| CVE-2021-46381 | HIGH | 7.5 | 58.0% | Mar 4, 2022 | Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd]... |
| CVE-2021-46380 | — | — | — | Mar 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: Reason: This is a duplicate to CVE-2022-22511 Notes |
| CVE-2021-46379 | MEDIUM | 6.1 | 15.7% | Mar 4, 2022 | DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust... |
| CVE-2021-3744 | MEDIUM | 5.5 | 0.5% | Mar 4, 2022 | A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now