2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39982 | CRITICAL | 9.1 | 0.6% | Jan 3, 2022 | Phone Manager application has a Improper Privilege Management vulnerability.Successful exploitation of this vulnerabilit... |
| CVE-2021-39979 | CRITICAL | 9.8 | 1.1% | Jan 3, 2022 | HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system inte... |
| CVE-2021-37128 | CRITICAL | 9.8 | 0.9% | Jan 3, 2022 | HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file. |
| CVE-2021-37121 | CRITICAL | 9.8 | 0.7% | Jan 3, 2022 | There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may elevate the MEID (IMEI)... |
| CVE-2021-37120 | CRITICAL | 9.8 | 0.9% | Jan 3, 2022 | There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel cras... |
| CVE-2021-37116 | CRITICAL | 9.1 | 0.7% | Jan 3, 2022 | PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cau... |
| CVE-2021-45428 | CRITICAL | 9.8 | 56.9% | Jan 3, 2022 | TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa... |
| CVE-2021-45917 | CRITICAL | 9 | 0.5% | Jan 3, 2022 | The server-request receiver function of Shockwall system has an improper authentication vulnerability. An authenticated ... |
| CVE-2021-30351 | CRITICAL | 9.8 | 4.0% | Jan 3, 2022 | An out of bound memory access can occur due to improper validation of number of frames being passed during music playbac... |
| CVE-2021-25981 | CRITICAL | 9.8 | 2.5% | Jan 3, 2022 | In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerab... |
| CVE-2021-45957 | CRITICAL | 9.8 | 2.4% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). N... |
| CVE-2021-45956 | CRITICAL | 9.8 | 2.6% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's p... |
| CVE-2021-45955 | CRITICAL | 9.8 | 2.5% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because... |
| CVE-2021-45954 | CRITICAL | 9.8 | 2.6% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's... |
| CVE-2021-45953 | CRITICAL | 9.8 | 2.6% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the ve... |
| CVE-2021-45952 | CRITICAL | 9.8 | 2.6% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's p... |
| CVE-2021-45951 | CRITICAL | 9.8 | 2.6% | Jan 1, 2022 | Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckFo... |
| CVE-2021-20158 | CRITICAL | 9.8 | 10.8% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauth... |
| CVE-2021-20155 | CRITICAL | 9.8 | 1.9% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore devi... |
| CVE-2021-20151 | CRITICAL | 10 | 1.6% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's manage... |
| CVE-2021-20149 | CRITICAL | 9.8 | 1.4% | Dec 30, 2021 | Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default i... |
| CVE-2021-45427 | CRITICAL | 9.8 | 19.0% | Dec 30, 2021 | Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An at... |
| CVE-2021-36722 | CRITICAL | 9.8 | 1.3% | Dec 29, 2021 | Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dum... |
| CVE-2021-38687 | CRITICAL | 9.8 | 1.3% | Dec 29, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, t... |
| CVE-2021-35034 | CRITICAL | 9.1 | 1.0% | Dec 29, 2021 | An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now