2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33644 | HIGH | 8.1 | 1.1% | Aug 10, 2022 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo... |
| CVE-2021-46304 | HIGH | 7.5 | 0.6% | Aug 10, 2022 | A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WI... |
| CVE-2021-37150 | HIGH | 7.5 | 1.7% | Aug 10, 2022 | Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure ... |
| CVE-2021-32771 | HIGH | 8.1 | 1.0% | Aug 4, 2022 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to ca... |
| CVE-2021-39088 | HIGH | 7.8 | 0.2% | Jul 28, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unkno... |
| CVE-2021-22642 | HIGH | 7.5 | 0.7% | Jul 28, 2022 | An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system. |
| CVE-2021-42537 | HIGH | 7.5 | 0.4% | Jul 27, 2022 | VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents... |
| CVE-2021-38417 | HIGH | 7.5 | 0.6% | Jul 27, 2022 | VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an un... |
| CVE-2021-38410 | HIGH | 7.8 | 0.2% | Jul 27, 2022 | AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijac... |
| CVE-2021-40180 | HIGH | 7.5 | 1.1% | Jul 26, 2022 | In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's addr... |
| CVE-2021-33057 | HIGH | 7.5 | 1.0% | Jul 26, 2022 | The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCE... |
| CVE-2021-33453 | HIGH | 7.8 | 0.3% | Jul 26, 2022 | An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538. |
| CVE-2021-40336 | HIGH | 8.8 | 0.4% | Jul 25, 2022 | A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This ... |
| CVE-2021-40335 | HIGH | 8.8 | 0.2% | Jul 25, 2022 | A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, ... |
| CVE-2021-46829 | HIGH | 7.8 | 0.7% | Jul 24, 2022 | GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames i... |
| CVE-2021-29755 | HIGH | 7.5 | 0.4% | Jul 20, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM... |
| CVE-2021-46828 | HIGH | 7.5 | 2.1% | Jul 20, 2022 | In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because... |
| CVE-2021-41031 | HIGH | 7.8 | 0.5% | Jul 18, 2022 | A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior an... |
| CVE-2021-44954 | HIGH | 7.8 | 0.3% | Jul 18, 2022 | In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a... |
| CVE-2021-42923 | HIGH | 7.3 | 0.2% | Jul 18, 2022 | ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-Sh... |
| CVE-2021-40150 | HIGH | 7.5 | 3.4% | Jul 17, 2022 | The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp... |
| CVE-2021-24655 | HIGH | 7.5 | 0.8% | Jul 17, 2022 | The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related t... |
| CVE-2021-34538 | HIGH | 7.5 | 1.4% | Jul 16, 2022 | Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved ... |
| CVE-2021-34987 | HIGH | 8.2 | 0.3% | Jul 15, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (... |
| CVE-2021-34986 | HIGH | 7.8 | 0.2% | Jul 15, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now