2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20298 | HIGH | 7.5 | 1.2% | Aug 23, 2022 | A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed ... |
| CVE-2021-28861 | HIGH | 7.4 | 2.0% | Aug 23, 2022 | Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multipl... |
| CVE-2021-3590 | HIGH | 8.8 | 0.6% | Aug 22, 2022 | A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password t... |
| CVE-2021-3513 | HIGH | 7.5 | 0.7% | Aug 22, 2022 | A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. ... |
| CVE-2021-3481 | HIGH | 7.1 | 0.5% | Aug 22, 2022 | A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/... |
| CVE-2021-37289 | HIGH | 7.2 | 1.4% | Aug 22, 2022 | Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system c... |
| CVE-2021-36852 | HIGH | 8 | 0.3% | Aug 22, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress. |
| CVE-2021-37409 | HIGH | 7.8 | 0.2% | Aug 18, 2022 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user ... |
| CVE-2021-33847 | HIGH | 7.8 | 0.2% | Aug 18, 2022 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products be... |
| CVE-2021-33060 | HIGH | 7.8 | 0.3% | Aug 18, 2022 | Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially ena... |
| CVE-2021-23223 | HIGH | 7.8 | 0.3% | Aug 18, 2022 | Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user ... |
| CVE-2021-23179 | HIGH | 7.1 | 0.2% | Aug 18, 2022 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi... |
| CVE-2021-30070 | HIGH | 7.5 | 0.6% | Aug 18, 2022 | An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values take... |
| CVE-2021-26639 | HIGH | 7.5 | 0.4% | Aug 17, 2022 | This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Re... |
| CVE-2021-45454 | HIGH | 7.5 | 0.6% | Aug 17, 2022 | Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon. |
| CVE-2021-42052 | HIGH | 7.5 | 0.9% | Aug 16, 2022 | IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEReso... |
| CVE-2021-30490 | HIGH | 7.8 | 0.3% | Aug 16, 2022 | upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binar... |
| CVE-2021-29117 | HIGH | 7.8 | 0.4% | Aug 12, 2022 | A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an un... |
| CVE-2021-44720 | HIGH | 7.2 | 2.3% | Aug 12, 2022 | In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source... |
| CVE-2021-40040 | HIGH | 7.5 | 0.5% | Aug 10, 2022 | Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulner... |
| CVE-2021-40034 | HIGH | 7.5 | 0.5% | Aug 10, 2022 | The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of thi... |
| CVE-2021-40030 | HIGH | 7.5 | 0.4% | Aug 10, 2022 | The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidential... |
| CVE-2021-39696 | HIGH | 7.8 | 0.2% | Aug 10, 2022 | In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation ... |
| CVE-2021-33646 | HIGH | 7.5 | 1.4% | Aug 10, 2022 | The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory ... |
| CVE-2021-33645 | HIGH | 7.5 | 1.4% | Aug 10, 2022 | The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now