2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45951 | CRITICAL | 9.8 | 2.6% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckFo... |
| CVE-2021-45950 | MEDIUM | 6.5 | 0.9% | Jan 1, 2022 | LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOC... |
| CVE-2021-45949 | MEDIUM | 5.5 | 1.4% | Jan 1, 2022 | Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_da... |
| CVE-2021-45948 | MEDIUM | 5.5 | 0.9% | Jan 1, 2022 | Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d... |
| CVE-2021-45947 | MEDIUM | 5.5 | 0.7% | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments). |
| CVE-2021-45946 | MEDIUM | 5.5 | 0.7% | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements). |
| CVE-2021-45945 | — | — | — | Jan 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-45944 | MEDIUM | 5.5 | 1.4% | Jan 1, 2022 | Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue ... |
| CVE-2021-45929 | MEDIUM | 5.5 | 0.7% | Jan 1, 2022 | Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If). |
| CVE-2021-4193 | MEDIUM | 5.5 | 1.8% | Dec 31, 2021 | vim is vulnerable to Out-of-bounds Read |
| CVE-2021-4192 | HIGH | 7.8 | 1.7% | Dec 31, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-4190 | HIGH | 7.5 | 3.1% | Dec 30, 2021 | Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture fi... |
| CVE-2021-4186 | HIGH | 7.5 | 2.2% | Dec 30, 2021 | Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted cap... |
| CVE-2021-4185 | HIGH | 7.5 | 3.9% | Dec 30, 2021 | Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injectio... |
| CVE-2021-4184 | HIGH | 7.5 | 3.9% | Dec 30, 2021 | Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet... |
| CVE-2021-4183 | MEDIUM | 5.5 | 1.4% | Dec 30, 2021 | Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file |
| CVE-2021-4182 | HIGH | 7.5 | 3.3% | Dec 30, 2021 | Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or ... |
| CVE-2021-4181 | HIGH | 7.5 | 3.8% | Dec 30, 2021 | Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection... |
| CVE-2021-45732 | HIGH | 8.8 | 0.8% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are ... |
| CVE-2021-45077 | HIGH | 7.5 | 0.6% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the... |
| CVE-2021-44466 | HIGH | 7.3 | 0.4% | Dec 30, 2021 | Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software ... |
| CVE-2021-23147 | MEDIUM | 6.8 | 0.4% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor w... |
| CVE-2021-20175 | HIGH | 7.5 | 0.6% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By defaul... |
| CVE-2021-20174 | HIGH | 7.5 | 0.6% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default... |
| CVE-2021-20173 | HIGH | 8.8 | 3.2% | Dec 30, 2021 | Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the devi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now