2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34235CRITICAL9.8Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the l...
CVE-2021-31932CRITICAL9.8Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can...
CVE-2021-22824HIGH7.5A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due t...
CVE-2021-22823CRITICAL9.1A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file...
CVE-2021-22806HIGH7.5A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unaut...
CVE-2021-22805CRITICAL9.1A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file...
CVE-2021-22804HIGH7.5A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure o...
CVE-2021-22803CRITICAL9.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution...
CVE-2021-22802CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution du...
CVE-2021-22801CRITICAL9.8A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the s...
CVE-2021-22800HIGH7.5A CWE-20: Improper Input Validation vulnerability exists that could cause a Denial of Service when a crafted packet is s...
CVE-2021-22798HIGH7.5A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login crede...
CVE-2021-22796HIGH7.8A CWE-287: Improper Authentication vulnerability exists that could allow remote code execution when a malicious file is ...
CVE-2021-22788HIGH7.5A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a speciall...
CVE-2021-22787HIGH7.5A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attack...
CVE-2021-22785HIGH7.5A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web ...
CVE-2021-22748HIGH8.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could...
CVE-2021-0524MEDIUM5.5In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure of installed packages ...
CVE-2021-45387MEDIUM5.5tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c.
CVE-2021-45386MEDIUM5.5tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c
CVE-2021-23597HIGH7.5This affects the package fastify-multipart before 5.3.1. By providing a name=constructor property it is still possible t...
CVE-2021-45385MEDIUM6.5A Null Pointer Dereference vulnerability exits in ffjpeg d5cfd49 (2021-12-06) in bmp_load(). When the size information i...
CVE-2021-42940CRITICAL9.9A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allow...
CVE-2021-45402MEDIUM5.5The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bound...
CVE-2021-38679CRITICAL9.8An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this v...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now