2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27464 | CRITICAL | 9.8 | 3.3% | Mar 23, 2022 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacki... |
| CVE-2021-27462 | CRITICAL | 9.8 | 3.7% | Mar 23, 2022 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre ... |
| CVE-2021-27460 | CRITICAL | 9.8 | 3.1% | Mar 23, 2022 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deseriali... |
| CVE-2021-27428 | CRITICAL | 9.8 | 1.2% | Mar 23, 2022 | GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervi... |
| CVE-2021-27426 | CRITICAL | 9.8 | 1.2% | Mar 23, 2022 | GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Fac... |
| CVE-2021-38278 | CRITICAL | 9.8 | 1.4% | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentCont... |
| CVE-2021-43736 | CRITICAL | 9.8 | 2.3% | Mar 23, 2022 | CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule |
| CVE-2021-43735 | CRITICAL | 9.8 | 1.2% | Mar 23, 2022 | CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule. |
| CVE-2021-45756 | CRITICAL | 9.8 | 1.7% | Mar 23, 2022 | Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.... |
| CVE-2021-41736 | CRITICAL | 9.8 | 1.4% | Mar 22, 2022 | Faust v2.35.0 was discovered to contain a heap-buffer overflow in the function realPropagate() at propagate.cpp. |
| CVE-2021-43650 | CRITICAL | 9.8 | 6.2% | Mar 22, 2022 | WebRun 3.6.0.42 is vulnerable to SQL Injection via the P_0 parameter used to set the username during the login process. |
| CVE-2021-45809 | CRITICAL | 9.8 | 1.6% | Mar 22, 2022 | GlobalProtect-openconnect versions prior to 1.4.3 are affected by incorrect access control in GPService through DBUS, GU... |
| CVE-2021-45878 | CRITICAL | 9.1 | 1.1% | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the we... |
| CVE-2021-45877 | CRITICAL | 9.8 | 1.1% | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /e... |
| CVE-2021-45876 | CRITICAL | 9.8 | 1.5% | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of th... |
| CVE-2021-39384 | CRITICAL | 9.8 | 1.2% | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.j... |
| CVE-2021-39383 | CRITICAL | 9.8 | 2.9% | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysP... |
| CVE-2021-45835 | CRITICAL | 9.8 | 3.0% | Mar 18, 2022 | The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the... |
| CVE-2021-45834 | CRITICAL | 9.8 | 2.3% | Mar 18, 2022 | An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass... |
| CVE-2021-45967 | CRITICAL | 9.8 | 20.8% | Mar 18, 2022 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To... |
| CVE-2021-45966 | CRITICAL | 9.8 | 5.6% | Mar 18, 2022 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.p... |
| CVE-2021-44088 | CRITICAL | 9.8 | 3.3% | Mar 17, 2022 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacke... |
| CVE-2021-44087 | CRITICAL | 9.8 | 4.7% | Mar 17, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an ... |
| CVE-2021-45040 | CRITICAL | 9.8 | 3.1% | Mar 17, 2022 | The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload... |
| CVE-2021-44906 | CRITICAL | 9.8 | 4.6% | Mar 17, 2022 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now