2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28962 | HIGH | 7.2 | 1.2% | Jan 31, 2022 | Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands. |
| CVE-2021-46101 | HIGH | 7.5 | 1.4% | Jan 31, 2022 | In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly. |
| CVE-2021-44255 | HIGH | 7.2 | 3.0% | Jan 31, 2022 | Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to uplo... |
| CVE-2021-23521 | HIGH | 7.8 | 0.5% | Jan 31, 2022 | This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is c... |
| CVE-2021-23520 | CRITICAL | 9.8 | 1.1% | Jan 31, 2022 | The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) vi... |
| CVE-2021-45079 | CRITICAL | 9.1 | 2.8% | Jan 31, 2022 | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticat... |
| CVE-2021-34805 | HIGH | 7.5 | 26.8% | Jan 31, 2022 | An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau ... |
| CVE-2021-27971 | HIGH | 7.8 | 0.4% | Jan 31, 2022 | Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection. |
| CVE-2021-46660 | CRITICAL | 9.8 | 1.1% | Jan 30, 2022 | Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. |
| CVE-2021-46659 | MEDIUM | 5.5 | 0.6% | Jan 29, 2022 | MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to ... |
| CVE-2021-46658 | MEDIUM | 5.5 | 0.4% | Jan 29, 2022 | save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_w... |
| CVE-2021-46657 | MEDIUM | 5.5 | 0.4% | Jan 29, 2022 | get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY. |
| CVE-2021-4160 | MEDIUM | 5.9 | 3.8% | Jan 28, 2022 | There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including... |
| CVE-2021-46448 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/customers.php?page=... |
| CVE-2021-46447 | MEDIUM | 5.4 | 0.5% | Jan 28, 2022 | A cross-site scripting (XSS) vulnerability in H.H.G Multistore v5.1.0 and below allows attackers to execute arbitrary we... |
| CVE-2021-46446 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad... |
| CVE-2021-46445 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/categories.php?box_... |
| CVE-2021-46444 | CRITICAL | 9.8 | 1.2% | Jan 28, 2022 | H.H.G Multistore v5.1.0 and below was discovered to contain a SQL injection vulnerability via /admin/admin.php?module=ad... |
| CVE-2021-44419 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44418 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44417 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44416 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44415 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44414 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
| CVE-2021-44413 | HIGH | 7.7 | 1.2% | Jan 28, 2022 | A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now