2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24867 | CRITICAL | 9.8 | 18.9% | Feb 21, 2022 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website bei... |
| CVE-2021-29656 | CRITICAL | 9.8 | 0.7% | Feb 18, 2022 | Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked. |
| CVE-2021-29655 | CRITICAL | 9.8 | 0.5% | Feb 18, 2022 | Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute. |
| CVE-2021-46110 | CRITICAL | 9.8 | 1.1% | Feb 18, 2022 | Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email an... |
| CVE-2021-46063 | CRITICAL | 9.1 | 2.7% | Feb 18, 2022 | MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management ... |
| CVE-2021-23702 | CRITICAL | 9.8 | 1.4% | Feb 18, 2022 | The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend. |
| CVE-2021-46036 | CRITICAL | 9.8 | 3.5% | Feb 18, 2022 | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to ex... |
| CVE-2021-45401 | CRITICAL | 9.8 | 2.5% | Feb 18, 2022 | A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.0... |
| CVE-2021-3657 | CRITICAL | 9.8 | 3.3% | Feb 18, 2022 | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals... |
| CVE-2021-26619 | CRITICAL | 9.1 | 0.9% | Feb 18, 2022 | An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can u... |
| CVE-2021-26618 | CRITICAL | 9.8 | 1.0% | Feb 18, 2022 | An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers u... |
| CVE-2021-20325 | CRITICAL | 9.8 | 1.6% | Feb 18, 2022 | Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5... |
| CVE-2021-46319 | CRITICAL | 9.8 | 6.2% | Feb 17, 2022 | Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-... |
| CVE-2021-46315 | CRITICAL | 9.8 | 6.2% | Feb 17, 2022 | Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846... |
| CVE-2021-46314 | CRITICAL | 9.8 | 33.3% | Feb 17, 2022 | A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router... |
| CVE-2021-45382 | CRITICAL | 9.8 | 97.8% | Feb 17, 2022 | A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L... |
| CVE-2021-44868 | CRITICAL | 9.8 | 1.4% | Feb 17, 2022 | A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do |
| CVE-2021-43303 | CRITICAL | 9.8 | 2.3% | Feb 16, 2022 | Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer o... |
| CVE-2021-43302 | CRITICAL | 9.1 | 2.2% | Feb 16, 2022 | Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause... |
| CVE-2021-43301 | CRITICAL | 9.8 | 2.3% | Feb 16, 2022 | Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a... |
| CVE-2021-43300 | CRITICAL | 9.8 | 2.3% | Feb 16, 2022 | Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a b... |
| CVE-2021-43299 | CRITICAL | 9.8 | 2.5% | Feb 16, 2022 | Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buf... |
| CVE-2021-3242 | CRITICAL | 9.8 | 1.2% | Feb 16, 2022 | DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=. |
| CVE-2021-3781 | CRITICAL | 9.9 | 83.9% | Feb 16, 2022 | A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting ... |
| CVE-2021-3773 | CRITICAL | 9.8 | 5.3% | Feb 16, 2022 | A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for furthe... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now