2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22657 | CRITICAL | 9.8 | 1.2% | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attac... |
| CVE-2021-44526 | CRITICAL | 9.8 | 3.2% | Dec 23, 2021 | Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. |
| CVE-2021-44548 | CRITICAL | 9.8 | 5.1% | Dec 23, 2021 | An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows U... |
| CVE-2021-38013 | CRITICAL | 9.6 | 1.0% | Dec 23, 2021 | Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote atta... |
| CVE-2021-45461 | CRITICAL | 9.8 | 21.7% | Dec 22, 2021 | FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remo... |
| CVE-2021-40418 | CRITICAL | 9.8 | 17.9% | Dec 22, 2021 | When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assig... |
| CVE-2021-40417 | CRITICAL | 9.8 | 15.7% | Dec 22, 2021 | When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decodin... |
| CVE-2021-40394 | CRITICAL | 9.8 | 2.9% | Dec 22, 2021 | An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.... |
| CVE-2021-40393 | CRITICAL | 9.8 | 3.1% | Dec 22, 2021 | An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.... |
| CVE-2021-39306 | CRITICAL | 9.8 | 1.3% | Dec 22, 2021 | A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an a... |
| CVE-2021-21952 | CRITICAL | 9.8 | 1.3% | Dec 22, 2021 | An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security b... |
| CVE-2021-21903 | CRITICAL | 9.8 | 1.7% | Dec 22, 2021 | A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Modu... |
| CVE-2021-21894 | CRITICAL | 9.1 | 2.4% | Dec 22, 2021 | A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0... |
| CVE-2021-21892 | CRITICAL | 9.9 | 30.4% | Dec 22, 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2... |
| CVE-2021-21891 | CRITICAL | 9.1 | 3.0% | Dec 22, 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWa... |
| CVE-2021-21890 | CRITICAL | 9.1 | 3.0% | Dec 22, 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWa... |
| CVE-2021-21889 | CRITICAL | 9.9 | 2.8% | Dec 22, 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8... |
| CVE-2021-21888 | CRITICAL | 9.1 | 3.9% | Dec 22, 2021 | An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix Premie... |
| CVE-2021-21887 | CRITICAL | 9.1 | 3.0% | Dec 22, 2021 | A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierW... |
| CVE-2021-21884 | CRITICAL | 9.1 | 5.3% | Dec 22, 2021 | An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 20... |
| CVE-2021-21883 | CRITICAL | 9.9 | 6.1% | Dec 22, 2021 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave... |
| CVE-2021-21881 | CRITICAL | 9.9 | 37.1% | Dec 22, 2021 | An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix Prem... |
| CVE-2021-21877 | CRITICAL | 9.1 | 2.7% | Dec 22, 2021 | Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenti... |
| CVE-2021-21876 | CRITICAL | 9.1 | 2.7% | Dec 22, 2021 | Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authentica... |
| CVE-2021-21875 | CRITICAL | 9.1 | 2.9% | Dec 22, 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now