2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40893 | HIGH | 7.5 | 1.1% | Jun 24, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating craf... |
| CVE-2021-40892 | HIGH | 7.5 | 1.1% | Jun 24, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling craft... |
| CVE-2021-41638 | HIGH | 7.5 | 1.6% | Jun 24, 2022 | The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to a... |
| CVE-2021-41637 | HIGH | 7.1 | 0.3% | Jun 24, 2022 | Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configurati... |
| CVE-2021-41635 | HIGH | 8.8 | 1.9% | Jun 24, 2022 | When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse... |
| CVE-2021-40956 | HIGH | 7.5 | 1.0% | Jun 23, 2022 | LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obta... |
| CVE-2021-40955 | HIGH | 7.2 | 0.9% | Jun 23, 2022 | SQL injection exists in LaiKetui v3.5.0 the background administrator list. |
| CVE-2021-40511 | HIGH | 7.5 | 0.9% | Jun 21, 2022 | OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service. |
| CVE-2021-40510 | HIGH | 7.5 | 1.2% | Jun 21, 2022 | XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs. |
| CVE-2021-41683 | HIGH | 7.8 | 0.7% | Jun 20, 2022 | There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0 |
| CVE-2021-41682 | HIGH | 7.8 | 0.7% | Jun 20, 2022 | There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.... |
| CVE-2021-45918 | HIGH | 7.5 | 1.4% | Jun 20, 2022 | NHI’s health insurance web service component has insufficient validation for input string length, which can result in he... |
| CVE-2021-45025 | HIGH | 7.5 | 0.7% | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to C... |
| CVE-2021-41490 | HIGH | 7.5 | 0.9% | Jun 17, 2022 | Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior. |
| CVE-2021-46820 | HIGH | 8.1 | 0.7% | Jun 16, 2022 | Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho... |
| CVE-2021-37764 | HIGH | 8.1 | 0.7% | Jun 16, 2022 | Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho... |
| CVE-2021-3675 | HIGH | 7.1 | 0.3% | Jun 16, 2022 | Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized ... |
| CVE-2021-41402 | HIGH | 8.8 | 1.3% | Jun 16, 2022 | flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP co... |
| CVE-2021-43755 | HIGH | 7.8 | 1.9% | Jun 15, 2022 | Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerab... |
| CVE-2021-42735 | HIGH | 7.8 | 2.0% | Jun 15, 2022 | Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer v... |
| CVE-2021-25261 | HIGH | 7.8 | 0.5% | Jun 15, 2022 | Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker... |
| CVE-2021-43756 | HIGH | 7.8 | 2.0% | Jun 15, 2022 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthe... |
| CVE-2021-43754 | HIGH | 7.8 | 1.5% | Jun 15, 2022 | Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling ... |
| CVE-2021-42732 | HIGH | 7.8 | 1.9% | Jun 15, 2022 | Access of Memory Location After End of Buffer (CWE-788) |
| CVE-2021-40727 | HIGH | 7.8 | 1.3% | Jun 15, 2022 | Access of Memory Location After End of Buffer (CWE-788 |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now