2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37589 | HIGH | 7.5 | 29.7% | Jun 7, 2022 | Virtua Cobranca before 12R allows SQL Injection on the login page. |
| CVE-2021-39947 | HIGH | 7.5 | 0.8% | Jun 6, 2022 | In specific circumstances, trace file buffers in GitLab Runner versions up to 14.3.4, 14.4 to 14.4.2, and 14.5 to 14.5.2... |
| CVE-2021-41932 | HIGH | 8.8 | 1.0% | Jun 6, 2022 | A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to... |
| CVE-2021-42893 | HIGH | 7.5 | 1.4% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization th... |
| CVE-2021-42891 | HIGH | 7.5 | 1.4% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization. |
| CVE-2021-42889 | HIGH | 7.5 | 1.4% | Jun 3, 2022 | In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without author... |
| CVE-2021-42886 | HIGH | 7.5 | 2.0% | Jun 3, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib conf... |
| CVE-2021-42877 | HIGH | 7.5 | 2.3% | Jun 2, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_... |
| CVE-2021-45982 | HIGH | 8.8 | 0.9% | Jun 2, 2022 | NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user. |
| CVE-2021-44080 | HIGH | 7.2 | 23.7% | Jun 2, 2022 | A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged... |
| CVE-2021-43308 | HIGH | 7.5 | 1.0% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package,... |
| CVE-2021-43307 | HIGH | 7.5 | 1.5% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an at... |
| CVE-2021-43306 | HIGH | 7.5 | 1.3% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when ... |
| CVE-2021-42204 | HIGH | 7.8 | 1.2% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() locate... |
| CVE-2021-42203 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_Defin... |
| CVE-2021-42201 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located... |
| CVE-2021-42199 | HIGH | 7.8 | 1.0% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_Defi... |
| CVE-2021-42197 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allo... |
| CVE-2021-42195 | HIGH | 7.8 | 0.9% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() loc... |
| CVE-2021-40186 | HIGH | 7.5 | 1.1% | Jun 2, 2022 | The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, fo... |
| CVE-2021-34083 | HIGH | 8.1 | 1.9% | Jun 2, 2022 | Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON... |
| CVE-2021-34081 | HIGH | 8.8 | 3.6% | Jun 2, 2022 | OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via ... |
| CVE-2021-34078 | HIGH | 8.8 | 2.5% | Jun 2, 2022 | lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scan... |
| CVE-2021-33615 | HIGH | 7.5 | 1.2% | Jun 2, 2022 | RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type. |
| CVE-2021-33254 | HIGH | 7.5 | 1.5% | Jun 2, 2022 | An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a d... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now