2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27406 | HIGH | 8.8 | 0.9% | Oct 14, 2022 | An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any a... |
| CVE-2021-22685 | HIGH | 7.5 | 0.6% | Oct 14, 2022 | An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controll... |
| CVE-2021-0699 | HIGH | 7.8 | 0.1% | Oct 14, 2022 | In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca... |
| CVE-2021-20030 | HIGH | 7.5 | 0.8% | Oct 13, 2022 | SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web ... |
| CVE-2021-36369 | HIGH | 7.5 | 1.3% | Oct 12, 2022 | An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication me... |
| CVE-2021-0951 | HIGH | 7.8 | 0.1% | Oct 11, 2022 | In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead... |
| CVE-2021-0696 | HIGH | 7 | 0.1% | Oct 11, 2022 | In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local e... |
| CVE-2021-36913 | HIGH | 7.5 | 0.5% | Oct 11, 2022 | Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= ... |
| CVE-2021-44171 | HIGH | 8 | 1.5% | Oct 10, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version... |
| CVE-2021-40166 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has ... |
| CVE-2021-40165 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond th... |
| CVE-2021-40164 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploite... |
| CVE-2021-40163 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Imag... |
| CVE-2021-40162 | HIGH | 7.8 | 0.2% | Oct 7, 2022 | A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond a... |
| CVE-2021-40556 | HIGH | 8.8 | 1.3% | Oct 6, 2022 | A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulne... |
| CVE-2021-33354 | HIGH | 8.1 | 1.3% | Sep 30, 2022 | Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via ... |
| CVE-2021-36854 | HIGH | 8.8 | 0.3% | Sep 30, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress. |
| CVE-2021-45788 | HIGH | 8.8 | 3.0% | Sep 29, 2022 | Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter. |
| CVE-2021-24890 | HIGH | 8.8 | 0.5% | Sep 26, 2022 | The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action... |
| CVE-2021-41803 | HIGH | 7.1 | 0.8% | Sep 23, 2022 | HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to inte... |
| CVE-2021-46836 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th... |
| CVE-2021-40024 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th... |
| CVE-2021-40023 | HIGH | 7.5 | 0.4% | Sep 16, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality... |
| CVE-2021-38924 | HIGH | 7.5 | 0.8% | Sep 14, 2022 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a det... |
| CVE-2021-0943 | HIGH | 7.8 | 0.1% | Sep 13, 2022 | In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to loc... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now