2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23682 | CRITICAL | 9.8 | 2.1% | Feb 16, 2022 | This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, befor... |
| CVE-2021-46250 | CRITICAL | 10 | 1.0% | Feb 15, 2022 | An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attacker... |
| CVE-2021-46321 | CRITICAL | 9.8 | 1.7% | Feb 15, 2022 | Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg modul... |
| CVE-2021-46265 | CRITICAL | 9.8 | 1.7% | Feb 15, 2022 | Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module... |
| CVE-2021-46264 | CRITICAL | 9.8 | 1.7% | Feb 15, 2022 | Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module.... |
| CVE-2021-46263 | CRITICAL | 9.8 | 1.7% | Feb 15, 2022 | Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. T... |
| CVE-2021-46262 | CRITICAL | 9.8 | 1.7% | Feb 15, 2022 | Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This... |
| CVE-2021-37354 | CRITICAL | 9.8 | 1.3% | Feb 15, 2022 | Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE... |
| CVE-2021-33945 | CRITICAL | 9.8 | 1.8% | Feb 15, 2022 | RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500S... |
| CVE-2021-43049 | CRITICAL | 9.8 | 1.3% | Feb 15, 2022 | The Database component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable v... |
| CVE-2021-4201 | CRITICAL | 9.8 | 1.9% | Feb 14, 2022 | Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthen... |
| CVE-2021-46463 | CRITICAL | 9.8 | 1.6% | Feb 14, 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerabili... |
| CVE-2021-46461 | CRITICAL | 9.8 | 3.1% | Feb 14, 2022 | njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/... |
| CVE-2021-45005 | CRITICAL | 9.8 | 1.4% | Feb 14, 2022 | Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested t... |
| CVE-2021-45420 | CRITICAL | 9.8 | 22.1% | Feb 14, 2022 | Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /... |
| CVE-2021-46362 | CRITICAL | 9.8 | 4.4% | Feb 11, 2022 | A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.... |
| CVE-2021-46361 | CRITICAL | 9.8 | 2.6% | Feb 11, 2022 | An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and e... |
| CVE-2021-23555 | CRITICAL | 9.8 | 2.7% | Feb 11, 2022 | The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node ... |
| CVE-2021-20001 | CRITICAL | 9.8 | 1.6% | Feb 11, 2022 | It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 co... |
| CVE-2021-39675 | CRITICAL | 9.8 | 5.9% | Feb 11, 2022 | In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead t... |
| CVE-2021-39658 | CRITICAL | 9.8 | 0.6% | Feb 11, 2022 | ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does ... |
| CVE-2021-39635 | CRITICAL | 9.1 | 0.5% | Feb 11, 2022 | ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions... |
| CVE-2021-39616 | CRITICAL | 9.8 | 0.6% | Feb 11, 2022 | Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438 |
| CVE-2021-34235 | CRITICAL | 9.8 | 1.9% | Feb 11, 2022 | Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the l... |
| CVE-2021-31932 | CRITICAL | 9.8 | 21.6% | Feb 11, 2022 | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now