2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26392 | HIGH | 7.8 | 0.3% | Nov 9, 2022 | Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing ... |
| CVE-2021-26391 | HIGH | 7.8 | 0.2% | Nov 9, 2022 | Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker w... |
| CVE-2021-26360 | HIGH | 7.8 | 0.2% | Nov 9, 2022 | An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC... |
| CVE-2021-34579 | HIGH | 7.5 | 0.6% | Nov 9, 2022 | In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of th... |
| CVE-2021-34568 | HIGH | 7.5 | 1.0% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co... |
| CVE-2021-34567 | HIGH | 8.2 | 0.8% | Nov 9, 2022 | In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co... |
| CVE-2021-39661 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a miss... |
| CVE-2021-1050 | HIGH | 7.8 | 0.2% | Nov 8, 2022 | In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. T... |
| CVE-2021-34055 | HIGH | 7.8 | 0.4% | Nov 4, 2022 | jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u. |
| CVE-2021-44862 | HIGH | 7.8 | 0.2% | Nov 3, 2022 | Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information sto... |
| CVE-2021-36906 | HIGH | 8.8 | 0.5% | Nov 3, 2022 | Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 ... |
| CVE-2021-45447 | HIGH | 7.5 | 0.3% | Nov 2, 2022 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage ... |
| CVE-2021-45446 | HIGH | 7.5 | 0.4% | Nov 2, 2022 | A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not ca... |
| CVE-2021-37789 | HIGH | 8.1 | 0.8% | Nov 2, 2022 | stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service... |
| CVE-2021-27784 | HIGH | 7.5 | 0.2% | Oct 31, 2022 | The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix pr... |
| CVE-2021-40661 | HIGH | 7.5 | 4.6% | Oct 31, 2022 | A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Adva... |
| CVE-2021-36898 | HIGH | 7.2 | 0.8% | Oct 28, 2022 | Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress. |
| CVE-2021-35387 | HIGH | 8.8 | 0.8% | Oct 28, 2022 | Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php. |
| CVE-2021-38399 | HIGH | 7.5 | 0.7% | Oct 28, 2022 | Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow... |
| CVE-2021-4228 | HIGH | 7.4 | 9.9% | Oct 24, 2022 | Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the ... |
| CVE-2021-46850 | HIGH | 7.2 | 5.2% | Oct 24, 2022 | myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An... |
| CVE-2021-46279 | HIGH | 8.8 | 0.4% | Oct 24, 2022 | Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attac... |
| CVE-2021-44467 | HIGH | 7.5 | 0.7% | Oct 24, 2022 | A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrari... |
| CVE-2021-26733 | HIGH | 7.5 | 0.7% | Oct 24, 2022 | A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to a... |
| CVE-2021-3305 | HIGH | 7.8 | 0.3% | Oct 18, 2022 | Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now