2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46568 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46567 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46566 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46565 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46564 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46563 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46562 | HIGH | 7.8 | 1.9% | Feb 18, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C... |
| CVE-2021-46082 | HIGH | 7.5 | 1.2% | Feb 18, 2022 | Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol g... |
| CVE-2021-46063 | CRITICAL | 9.1 | 2.7% | Feb 18, 2022 | MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management ... |
| CVE-2021-46062 | HIGH | 7.1 | 0.8% | Feb 18, 2022 | MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName. |
| CVE-2021-23702 | CRITICAL | 9.8 | 1.4% | Feb 18, 2022 | The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend. |
| CVE-2021-46037 | HIGH | 8.1 | 1.0% | Feb 18, 2022 | MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do. |
| CVE-2021-46036 | CRITICAL | 9.8 | 3.5% | Feb 18, 2022 | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to ex... |
| CVE-2021-4093 | HIGH | 8.8 | 0.4% | Feb 18, 2022 | A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KV... |
| CVE-2021-4091 | HIGH | 7.5 | 2.0% | Feb 18, 2022 | A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker co... |
| CVE-2021-4090 | HIGH | 7.1 | 0.3% | Feb 18, 2022 | An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write b... |
| CVE-2021-45401 | CRITICAL | 9.8 | 2.5% | Feb 18, 2022 | A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.0... |
| CVE-2021-44968 | HIGH | 7.8 | 0.4% | Feb 18, 2022 | A Use after Free vulnerability exists in IOBit Advanced SystemCare 15 pro via requests sent in sequential order using th... |
| CVE-2021-3948 | MEDIUM | 6.3 | 0.6% | Feb 18, 2022 | An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces h... |
| CVE-2021-3947 | MEDIUM | 5.5 | 0.3% | Feb 18, 2022 | A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a maliciou... |
| CVE-2021-3930 | MEDIUM | 6.5 | 0.3% | Feb 18, 2022 | An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands... |
| CVE-2021-3657 | CRITICAL | 9.8 | 3.3% | Feb 18, 2022 | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals... |
| CVE-2021-39026 | MEDIUM | 5.9 | 0.5% | Feb 18, 2022 | IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, ca... |
| CVE-2021-38935 | HIGH | 7.5 | 1.0% | Feb 18, 2022 | IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it ... |
| CVE-2021-30650 | MEDIUM | 6.1 | 0.7% | Feb 18, 2022 | A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now