2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44458 | CRITICAL | 9.6 | 0.4% | Jan 10, 2022 | Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website c... |
| CVE-2021-43297 | CRITICAL | 9.8 | 15.3% | Jan 10, 2022 | A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malic... |
| CVE-2021-25032 | CRITICAL | 9.8 | 6.7% | Jan 10, 2022 | The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1... |
| CVE-2021-24949 | CRITICAL | 9.8 | 1.7% | Jan 10, 2022 | The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise an... |
| CVE-2021-45334 | CRITICAL | 9.8 | 2.8% | Jan 10, 2022 | Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentic... |
| CVE-2021-45003 | CRITICAL | 9.8 | 3.0% | Jan 10, 2022 | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulne... |
| CVE-2021-42392 | CRITICAL | 9.8 | 63.2% | Jan 10, 2022 | The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and U... |
| CVE-2021-40010 | CRITICAL | 9.8 | 1.2% | Jan 10, 2022 | The bone voice ID TA has a heap overflow vulnerability.Successful exploitation of this vulnerability may result in malic... |
| CVE-2021-39996 | CRITICAL | 9.8 | 0.8% | Jan 10, 2022 | There is a Heap-based buffer overflow vulnerability with the NFC module in smartphones. Successful exploitation of this ... |
| CVE-2021-39993 | CRITICAL | 9.8 | 0.8% | Jan 10, 2022 | There is an Integer overflow vulnerability with ACPU in smartphones. Successful exploitation of this vulnerability may c... |
| CVE-2021-23594 | CRITICAL | 10 | 1.8% | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
| CVE-2021-23568 | CRITICAL | 9.8 | 1.5% | Jan 10, 2022 | The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive m... |
| CVE-2021-23543 | CRITICAL | 9.8 | 1.8% | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
| CVE-2021-46067 | CRITICAL | 9.8 | 5.1% | Jan 6, 2022 | In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover. |
| CVE-2021-45456 | CRITICAL | 9.8 | 88.6% | Jan 6, 2022 | Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the ... |
| CVE-2021-31522 | CRITICAL | 9.8 | 2.9% | Jan 6, 2022 | Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.... |
| CVE-2021-41842 | CRITICAL | 9.8 | 1.5% | Jan 6, 2022 | An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3... |
| CVE-2021-43816 | CRITICAL | 9.1 | 1.7% | Jan 5, 2022 | containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or S... |
| CVE-2021-43779 | CRITICAL | 9.9 | 9.1% | Jan 5, 2022 | GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in... |
| CVE-2021-43832 | CRITICAL | 9.8 | 2.6% | Jan 4, 2022 | Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipel... |
| CVE-2021-24042 | CRITICAL | 9.8 | 1.2% | Jan 4, 2022 | The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp ... |
| CVE-2021-45389 | CRITICAL | 9.8 | 1.2% | Jan 4, 2022 | A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the au... |
| CVE-2021-43711 | CRITICAL | 9.8 | 36.3% | Jan 4, 2022 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when re... |
| CVE-2021-40525 | CRITICAL | 9.1 | 3.7% | Jan 4, 2022 | Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path travers... |
| CVE-2021-39990 | CRITICAL | 9.8 | 0.8% | Jan 3, 2022 | The screen lock module has a Stack-based Buffer Overflow vulnerability.Successful exploitation of this vulnerability may... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now