2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38471 | CRITICAL | 9.1 | 1.0% | Oct 22, 2021 | There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existi... |
| CVE-2021-38469 | HIGH | 7.1 | 0.6% | Oct 22, 2021 | Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker c... |
| CVE-2021-38467 | HIGH | 8.1 | 0.7% | Oct 22, 2021 | A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then con... |
| CVE-2021-38465 | MEDIUM | 6.5 | 0.8% | Oct 22, 2021 | The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consum... |
| CVE-2021-38463 | HIGH | 8.1 | 0.7% | Oct 22, 2021 | The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited mem... |
| CVE-2021-38461 | HIGH | 8.2 | 0.5% | Oct 22, 2021 | The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted... |
| CVE-2021-38459 | CRITICAL | 9.8 | 1.0% | Oct 22, 2021 | The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specifi... |
| CVE-2021-38457 | CRITICAL | 9.8 | 1.3% | Oct 22, 2021 | The server permits communication without any authentication procedure, allowing the attacker to initiate a session with ... |
| CVE-2021-38455 | MEDIUM | 6.5 | 0.7% | Oct 22, 2021 | The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will... |
| CVE-2021-38453 | CRITICAL | 9.1 | 1.0% | Oct 22, 2021 | Some API functions allow interaction with the registry, which includes reading values as well as data modification. |
| CVE-2021-38451 | MEDIUM | 5.7 | 0.6% | Oct 22, 2021 | The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those funct... |
| CVE-2021-38449 | CRITICAL | 9.8 | 1.2% | Oct 22, 2021 | Some API functions permit by-design writing or copying data into a given buffer. Since the client controls these paramet... |
| CVE-2021-36357 | CRITICAL | 9.8 | 1.1% | Oct 22, 2021 | An issue was discovered in OpenPOWER 2.6 firmware. unpack_timestamp() calls le32_to_cpu() for endian conversion of a uin... |
| CVE-2021-35230 | MEDIUM | 6.7 | 0.3% | Oct 22, 2021 | As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker... |
| CVE-2021-31682 | MEDIUM | 6.1 | 10.5% | Oct 22, 2021 | The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re... |
| CVE-2021-31835 | MEDIUM | 4.8 | 0.5% | Oct 22, 2021 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrator... |
| CVE-2021-31834 | MEDIUM | 5.4 | 0.4% | Oct 22, 2021 | Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO admini... |
| CVE-2021-34362 | HIGH | 7.2 | 1.3% | Oct 22, 2021 | A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, ... |
| CVE-2021-41169 | MEDIUM | 4.8 | 0.6% | Oct 21, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subje... |
| CVE-2021-41127 | HIGH | 7.1 | 0.7% | Oct 21, 2021 | Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a... |
| CVE-2021-36869 | MEDIUM | 6.1 | 0.7% | Oct 21, 2021 | Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable para... |
| CVE-2021-27746 | MEDIUM | 5.4 | 0.5% | Oct 21, 2021 | "HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability" |
| CVE-2021-41168 | MEDIUM | 6.5 | 0.9% | Oct 21, 2021 | Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affec... |
| CVE-2021-40719 | CRITICAL | 9.8 | 3.4% | Oct 21, 2021 | Adobe Connect version 11.2.3 (and earlier) is affected by a Deserialization of Untrusted Data vulnerability to achieve a... |
| CVE-2021-39357 | MEDIUM | 4.8 | 0.9% | Oct 21, 2021 | The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now