2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43926 | CRITICAL | 9.8 | 0.9% | Feb 7, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun... |
| CVE-2021-43925 | CRITICAL | 9.8 | 0.9% | Feb 7, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun... |
| CVE-2021-41816 | CRITICAL | 9.8 | 4.8% | Feb 6, 2022 | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a lo... |
| CVE-2021-39280 | HIGH | 8.8 | 2.2% | Feb 6, 2022 | Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affect... |
| CVE-2021-38172 | CRITICAL | 9.8 | 1.8% | Feb 5, 2022 | perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.) |
| CVE-2021-4154 | HIGH | 8.8 | 1.2% | Feb 4, 2022 | A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 pars... |
| CVE-2021-4043 | MEDIUM | 5.5 | 4.8% | Feb 4, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0. |
| CVE-2021-44779 | CRITICAL | 9.8 | 1.1% | Feb 4, 2022 | Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3),... |
| CVE-2021-44206 | HIGH | 7.3 | 0.2% | Feb 4, 2022 | Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products a... |
| CVE-2021-44205 | HIGH | 7.3 | 0.2% | Feb 4, 2022 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2021-44204 | HIGH | 7.8 | 0.2% | Feb 4, 2022 | Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Ac... |
| CVE-2021-43841 | MEDIUM | 5.4 | 0.9% | Feb 4, 2022 | XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki... |
| CVE-2021-40420 | HIGH | 8.8 | 4.4% | Feb 4, 2022 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A s... |
| CVE-2021-40403 | MEDIUM | 6.3 | 1.1% | Feb 4, 2022 | An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and d... |
| CVE-2021-40401 | HIGH | 8.6 | 1.2% | Feb 4, 2022 | A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and d... |
| CVE-2021-38960 | HIGH | 7.5 | 1.0% | Feb 4, 2022 | IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID:... |
| CVE-2021-38130 | MEDIUM | 6.5 | 0.8% | Feb 4, 2022 | A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Rel... |
| CVE-2021-36152 | CRITICAL | 9.8 | 1.3% | Feb 4, 2022 | Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.... |
| CVE-2021-36151 | MEDIUM | 5.5 | 0.4% | Feb 4, 2022 | In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. T... |
| CVE-2021-32732 | MEDIUM | 6.5 | 0.9% | Feb 4, 2022 | ### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which userna... |
| CVE-2021-32036 | HIGH | 7.1 | 1.0% | Feb 4, 2022 | An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at... |
| CVE-2021-29219 | HIGH | 7.8 | 0.2% | Feb 4, 2022 | A potential local buffer overflow vulnerability has been identified in HPE FlexNetwork 5130 EL Switch Series version: Pr... |
| CVE-2021-29218 | MEDIUM | 6.7 | 0.2% | Feb 4, 2022 | A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows ... |
| CVE-2021-28503 | CRITICAL | 9.8 | 0.7% | Feb 4, 2022 | The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate base... |
| CVE-2021-22288 | HIGH | 7.5 | 1.0% | Feb 4, 2022 | Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now