2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22823 | CRITICAL | 9.1 | 21.4% | Feb 11, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file... |
| CVE-2021-22805 | CRITICAL | 9.1 | 0.8% | Feb 11, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary file... |
| CVE-2021-22803 | CRITICAL | 9.8 | 1.9% | Feb 11, 2022 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution... |
| CVE-2021-22802 | CRITICAL | 9.8 | 20.2% | Feb 11, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution du... |
| CVE-2021-22801 | CRITICAL | 9.8 | 1.5% | Feb 11, 2022 | A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the s... |
| CVE-2021-42940 | CRITICAL | 9.9 | 1.1% | Feb 11, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allow... |
| CVE-2021-38679 | CRITICAL | 9.8 | 0.7% | Feb 11, 2022 | An improper authentication vulnerability has been reported to affect QNAP NAS running Kazoo Server. If exploited, this v... |
| CVE-2021-44521 | CRITICAL | 9.1 | 54.9% | Feb 11, 2022 | When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user... |
| CVE-2021-35068 | CRITICAL | 9.8 | 0.5% | Feb 11, 2022 | Lack of null check while freeing the device information buffer in the Bluetooth HFP protocol can lead to a NULL pointer ... |
| CVE-2021-45364 | CRITICAL | 9.8 | 1.6% | Feb 10, 2022 | A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor in... |
| CVE-2021-25992 | CRITICAL | 9.8 | 1.5% | Feb 10, 2022 | In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It ... |
| CVE-2021-39997 | CRITICAL | 9.8 | 0.8% | Feb 9, 2022 | There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this ... |
| CVE-2021-39994 | CRITICAL | 9.8 | 0.8% | Feb 9, 2022 | There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulne... |
| CVE-2021-26616 | CRITICAL | 9.8 | 0.9% | Feb 9, 2022 | An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand ar... |
| CVE-2021-36302 | CRITICAL | 9.9 | 0.9% | Feb 9, 2022 | All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A re... |
| CVE-2021-45331 | CRITICAL | 9.8 | 1.3% | Feb 9, 2022 | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. I... |
| CVE-2021-45330 | CRITICAL | 9.8 | 1.4% | Feb 9, 2022 | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not... |
| CVE-2021-45327 | CRITICAL | 9.8 | 2.1% | Feb 8, 2022 | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable a... |
| CVE-2021-25114 | CRITICAL | 9.8 | 82.2% | Feb 7, 2022 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail... |
| CVE-2021-43927 | CRITICAL | 9.8 | 0.9% | Feb 7, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Managemen... |
| CVE-2021-43926 | CRITICAL | 9.8 | 0.9% | Feb 7, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun... |
| CVE-2021-43925 | CRITICAL | 9.8 | 0.9% | Feb 7, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log Management fun... |
| CVE-2021-41816 | CRITICAL | 9.8 | 4.8% | Feb 6, 2022 | CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a lo... |
| CVE-2021-38172 | CRITICAL | 9.8 | 1.8% | Feb 5, 2022 | perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.) |
| CVE-2021-44779 | CRITICAL | 9.8 | 1.1% | Feb 4, 2022 | Unauthenticated SQL Injection (SQLi) vulnerability discovered in [GWA] AutoResponder WordPress plugin (versions <= 2.3),... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now