2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34235 | CRITICAL | 9.8 | 1.9% | Feb 11, 2022 | Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the l... |
| CVE-2021-31932 | CRITICAL | 9.8 | 21.6% | Feb 11, 2022 | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can... |
| CVE-2021-22824 | HIGH | 7.5 | 14.2% | Feb 11, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due t... |
| CVE-2021-22823 | CRITICAL | 9.1 | 21.4% | Feb 11, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file... |
| CVE-2021-22806 | HIGH | 7.5 | 0.9% | Feb 11, 2022 | A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unaut... |
| CVE-2021-22805 | CRITICAL | 9.1 | 0.8% | Feb 11, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file... |
| CVE-2021-22804 | HIGH | 7.5 | 1.3% | Feb 11, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure o... |
| CVE-2021-22803 | CRITICAL | 9.8 | 1.9% | Feb 11, 2022 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution... |
| CVE-2021-22802 | CRITICAL | 9.8 | 20.2% | Feb 11, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution du... |
| CVE-2021-22801 | CRITICAL | 9.8 | 1.5% | Feb 11, 2022 | A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the s... |
| CVE-2021-22800 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is s... |
| CVE-2021-22798 | HIGH | 7.5 | 0.9% | Feb 11, 2022 | A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login crede... |
| CVE-2021-22796 | HIGH | 7.8 | 1.2% | Feb 11, 2022 | A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is ... |
| CVE-2021-22788 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a speciall... |
| CVE-2021-22787 | HIGH | 7.5 | 1.0% | Feb 11, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attack... |
| CVE-2021-22785 | HIGH | 7.5 | 1.1% | Feb 11, 2022 | A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web ... |
| CVE-2021-22748 | HIGH | 8.8 | 1.8% | Feb 11, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could... |
| CVE-2021-0524 | MEDIUM | 5.5 | 0.1% | Feb 11, 2022 | In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages ... |
| CVE-2021-45387 | MEDIUM | 5.5 | 0.7% | Feb 11, 2022 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. |
| CVE-2021-45386 | MEDIUM | 5.5 | 0.7% | Feb 11, 2022 | tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c |
| CVE-2021-23597 | HIGH | 7.5 | 2.0% | Feb 11, 2022 | This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible t... |
| CVE-2021-45385 | MEDIUM | 6.5 | 0.9% | Feb 11, 2022 | A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information i... |
| CVE-2021-42940 | CRITICAL | 9.9 | 1.1% | Feb 11, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allow... |
| CVE-2021-45402 | MEDIUM | 5.5 | 0.4% | Feb 11, 2022 | The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bound... |
| CVE-2021-38679 | CRITICAL | 9.8 | 0.7% | Feb 11, 2022 | An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this v... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now