2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40161 | HIGH | 7.8 | 1.4% | Dec 23, 2021 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earli... |
| CVE-2021-40160 | HIGH | 7.8 | 1.5% | Dec 23, 2021 | PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF ... |
| CVE-2021-4118 | HIGH | 7.8 | 1.0% | Dec 23, 2021 | pytorch-lightning is vulnerable to Deserialization of Untrusted Data |
| CVE-2021-43854 | HIGH | 7.5 | 2.7% | Dec 23, 2021 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2021-43849 | MEDIUM | 5.5 | 0.3% | Dec 23, 2021 | cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both... |
| CVE-2021-3892 | — | — | — | Dec 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-18198. Reason: This candidate is a reservation d... |
| CVE-2021-23175 | HIGH | 8.2 | 0.4% | Dec 23, 2021 | NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply indi... |
| CVE-2021-44526 | CRITICAL | 9.8 | 3.2% | Dec 23, 2021 | Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. |
| CVE-2021-44600 | HIGH | 7.5 | 1.3% | Dec 23, 2021 | The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injectio... |
| CVE-2021-44599 | HIGH | 7.5 | 1.2% | Dec 23, 2021 | The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. ... |
| CVE-2021-44273 | HIGH | 7.4 | 1.0% | Dec 23, 2021 | e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mod... |
| CVE-2021-44548 | CRITICAL | 9.8 | 5.1% | Dec 23, 2021 | An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows U... |
| CVE-2021-4144 | HIGH | 8.8 | 1.9% | Dec 23, 2021 | TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection. |
| CVE-2021-45463 | HIGH | 7.8 | 1.4% | Dec 23, 2021 | load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or ... |
| CVE-2021-45462 | HIGH | 7.5 | 4.4% | Dec 23, 2021 | In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF. |
| CVE-2021-20050 | HIGH | 7.5 | 0.9% | Dec 23, 2021 | An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessi... |
| CVE-2021-20049 | HIGH | 7.5 | 1.3% | Dec 23, 2021 | A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 usern... |
| CVE-2021-4079 | HIGH | 8.8 | 0.8% | Dec 23, 2021 | Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit he... |
| CVE-2021-4078 | HIGH | 8.8 | 1.0% | Dec 23, 2021 | Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2021-4068 | MEDIUM | 6.5 | 1.3% | Dec 23, 2021 | Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cr... |
| CVE-2021-4067 | HIGH | 8.8 | 1.2% | Dec 23, 2021 | Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potenti... |
| CVE-2021-4066 | HIGH | 8.8 | 1.4% | Dec 23, 2021 | Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap ... |
| CVE-2021-4065 | HIGH | 8.8 | 1.2% | Dec 23, 2021 | Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap ... |
| CVE-2021-4064 | HIGH | 8.8 | 1.3% | Dec 23, 2021 | Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potenti... |
| CVE-2021-4063 | HIGH | 8.8 | 1.3% | Dec 23, 2021 | Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now