2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44860 | HIGH | 7.8 | 0.8% | Dec 21, 2021 | An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.1... |
| CVE-2021-44859 | HIGH | 7.8 | 0.8% | Dec 21, 2021 | An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.1... |
| CVE-2021-44423 | HIGH | 7.8 | 0.8% | Dec 21, 2021 | An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer be... |
| CVE-2021-44422 | HIGH | 7.8 | 0.9% | Dec 21, 2021 | An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before... |
| CVE-2021-38966 | MEDIUM | 5.4 | 0.5% | Dec 21, 2021 | IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2021-38900 | MEDIUM | 6.5 | 1.1% | Dec 21, 2021 | IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a pr... |
| CVE-2021-38893 | MEDIUM | 5.4 | 0.7% | Dec 21, 2021 | IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable t... |
| CVE-2021-45293 | MEDIUM | 5.5 | 0.8% | Dec 21, 2021 | A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinar... |
| CVE-2021-45292 | MEDIUM | 5.5 | 0.6% | Dec 21, 2021 | The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address d... |
| CVE-2021-45291 | MEDIUM | 5.5 | 0.6% | Dec 21, 2021 | The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address der... |
| CVE-2021-45290 | HIGH | 7.5 | 1.5% | Dec 21, 2021 | A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable. |
| CVE-2021-45289 | MEDIUM | 5.5 | 0.6% | Dec 21, 2021 | A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of ... |
| CVE-2021-44207 | HIGH | 8.1 | 17.6% | Dec 21, 2021 | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. |
| CVE-2021-27453 | CRITICAL | 9.8 | 1.0% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application,... |
| CVE-2021-27451 | CRITICAL | 9.8 | 0.8% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an... |
| CVE-2021-27449 | HIGH | 8.8 | 3.1% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute comman... |
| CVE-2021-27447 | CRITICAL | 9.8 | 2.3% | Dec 21, 2021 | Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute ar... |
| CVE-2021-27445 | HIGH | 7.8 | 0.2% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges ... |
| CVE-2021-45288 | MEDIUM | 5.5 | 0.6% | Dec 21, 2021 | A Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file... |
| CVE-2021-44877 | HIGH | 7.5 | 1.0% | Dec 21, 2021 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP s... |
| CVE-2021-44876 | MEDIUM | 5.3 | 0.8% | Dec 21, 2021 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system th... |
| CVE-2021-44875 | MEDIUM | 5.3 | 0.8% | Dec 21, 2021 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system th... |
| CVE-2021-44874 | HIGH | 8.8 | 1.0% | Dec 21, 2021 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam ap... |
| CVE-2021-43839 | HIGH | 7.5 | 1.3% | Dec 21, 2021 | Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to... |
| CVE-2021-43587 | MEDIUM | 6.7 | 0.2% | Dec 21, 2021 | Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now