2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36152 | CRITICAL | 9.8 | 1.3% | Feb 4, 2022 | Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.... |
| CVE-2021-28503 | CRITICAL | 9.8 | 0.7% | Feb 4, 2022 | The impact of this vulnerability is that Arista's EOS eAPI may skip re-evaluating user credentials when certificate base... |
| CVE-2021-21965 | CRITICAL | 9.3 | 1.0% | Feb 4, 2022 | A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaC... |
| CVE-2021-21961 | CRITICAL | 10 | 2.5% | Feb 4, 2022 | A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v... |
| CVE-2021-21960 | CRITICAL | 10 | 2.5% | Feb 4, 2022 | A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect ... |
| CVE-2021-23507 | CRITICAL | 9.8 | 2.1% | Feb 4, 2022 | The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an a... |
| CVE-2021-23497 | CRITICAL | 9.8 | 3.5% | Feb 4, 2022 | This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead ... |
| CVE-2021-23470 | CRITICAL | 9.8 | 1.2% | Feb 4, 2022 | This affects the package putil-merge before 3.8.0. The merge() function does not check the values passed into the argume... |
| CVE-2021-29396 | CRITICAL | 9.8 | 1.6% | Feb 4, 2022 | Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated ... |
| CVE-2021-29393 | CRITICAL | 9.8 | 3.4% | Feb 4, 2022 | Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allo... |
| CVE-2021-44978 | CRITICAL | 9.8 | 2.1% | Feb 4, 2022 | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code ... |
| CVE-2021-46457 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgS... |
| CVE-2021-46456 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetW... |
| CVE-2021-46455 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetS... |
| CVE-2021-46454 | CRITICAL | 9.8 | 4.8% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetW... |
| CVE-2021-46453 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetS... |
| CVE-2021-46452 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetN... |
| CVE-2021-46233 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_... |
| CVE-2021-46232 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function vers... |
| CVE-2021-46231 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlr... |
| CVE-2021-46230 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgr... |
| CVE-2021-46229 | CRITICAL | 9.8 | 4.2% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_... |
| CVE-2021-46228 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function http... |
| CVE-2021-46227 | CRITICAL | 9.8 | 5.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function prox... |
| CVE-2021-46226 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now