2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26619 | CRITICAL | 9.1 | 0.9% | Feb 18, 2022 | An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can u... |
| CVE-2021-26618 | CRITICAL | 9.8 | 1.0% | Feb 18, 2022 | An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers u... |
| CVE-2021-20325 | CRITICAL | 9.8 | 1.6% | Feb 18, 2022 | Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5... |
| CVE-2021-20322 | HIGH | 7.4 | 6.8% | Feb 18, 2022 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functional... |
| CVE-2021-20321 | MEDIUM | 4.7 | 0.2% | Feb 18, 2022 | A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in s... |
| CVE-2021-20320 | MEDIUM | 5.5 | 0.3% | Feb 18, 2022 | A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a l... |
| CVE-2021-20315 | MEDIUM | 6.1 | 0.2% | Feb 18, 2022 | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "... |
| CVE-2021-46372 | MEDIUM | 5.4 | 0.6% | Feb 18, 2022 | Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to... |
| CVE-2021-46108 | MEDIUM | 5.4 | 0.8% | Feb 18, 2022 | D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance config... |
| CVE-2021-41599 | HIGH | 8.8 | 2.1% | Feb 18, 2022 | A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a... |
| CVE-2021-4120 | HIGH | 7.8 | 0.4% | Feb 17, 2022 | snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability... |
| CVE-2021-44731 | HIGH | 7.8 | 1.0% | Feb 17, 2022 | A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. Th... |
| CVE-2021-44730 | HIGH | 8.8 | 0.3% | Feb 17, 2022 | snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this b... |
| CVE-2021-3155 | MEDIUM | 5.5 | 0.3% | Feb 17, 2022 | snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. ... |
| CVE-2021-46319 | CRITICAL | 9.8 | 6.2% | Feb 17, 2022 | Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-... |
| CVE-2021-46315 | CRITICAL | 9.8 | 6.2% | Feb 17, 2022 | Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846... |
| CVE-2021-46314 | CRITICAL | 9.8 | 33.3% | Feb 17, 2022 | A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router... |
| CVE-2021-45382 | CRITICAL | 9.8 | 97.8% | Feb 17, 2022 | A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L... |
| CVE-2021-46247 | HIGH | 7.5 | 1.2% | Feb 17, 2022 | The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from A... |
| CVE-2021-39034 | HIGH | 7.5 | 1.2% | Feb 17, 2022 | IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID... |
| CVE-2021-44868 | CRITICAL | 9.8 | 1.4% | Feb 17, 2022 | A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do |
| CVE-2021-46368 | HIGH | 7.8 | 0.4% | Feb 17, 2022 | TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes wi... |
| CVE-2021-43303 | CRITICAL | 9.8 | 2.3% | Feb 16, 2022 | Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer o... |
| CVE-2021-43302 | CRITICAL | 9.1 | 2.2% | Feb 16, 2022 | Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause... |
| CVE-2021-43301 | CRITICAL | 9.8 | 2.3% | Feb 16, 2022 | Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now