2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32546 | HIGH | 8.8 | 2.0% | Jun 2, 2022 | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely... |
| CVE-2021-26635 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target... |
| CVE-2021-3555 | HIGH | 8.8 | 0.7% | May 31, 2022 | A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to ... |
| CVE-2021-33014 | HIGH | 8.8 | 0.8% | May 26, 2022 | An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versio... |
| CVE-2021-34360 | HIGH | 8.8 | 0.4% | May 26, 2022 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If explo... |
| CVE-2021-40317 | HIGH | 8.8 | 0.9% | May 26, 2022 | Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter. |
| CVE-2021-42860 | HIGH | 7.5 | 1.0% | May 26, 2022 | A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it wil... |
| CVE-2021-42859 | HIGH | 7.5 | 1.0% | May 26, 2022 | A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inco... |
| CVE-2021-44719 | HIGH | 8.4 | 0.3% | May 25, 2022 | Docker Desktop 4.3.0 has Incorrect Access Control. |
| CVE-2021-32997 | HIGH | 7.5 | 0.3% | May 25, 2022 | The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 Sys... |
| CVE-2021-32966 | HIGH | 7.5 | 0.4% | May 25, 2022 | Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text t... |
| CVE-2021-42614 | HIGH | 7.8 | 0.8% | May 24, 2022 | A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or ... |
| CVE-2021-42613 | HIGH | 7.8 | 0.8% | May 24, 2022 | A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly hav... |
| CVE-2021-42612 | HIGH | 7.8 | 0.8% | May 24, 2022 | A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly... |
| CVE-2021-3717 | HIGH | 7.8 | 0.3% | May 24, 2022 | A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may l... |
| CVE-2021-32969 | HIGH | 7.8 | 1.1% | May 24, 2022 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result... |
| CVE-2021-32965 | HIGH | 7.8 | 1.1% | May 24, 2022 | Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to rem... |
| CVE-2021-4230 | HIGH | 7.5 | 0.9% | May 24, 2022 | A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /ba... |
| CVE-2021-4229 | HIGH | 8.8 | 1.3% | May 24, 2022 | A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the cryp... |
| CVE-2021-42655 | HIGH | 8.8 | 1.1% | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. |
| CVE-2021-42586 | HIGH | 8.8 | 1.0% | May 23, 2022 | A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. |
| CVE-2021-42585 | HIGH | 8.8 | 1.0% | May 23, 2022 | A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted ... |
| CVE-2021-30028 | HIGH | 7.2 | 1.3% | May 20, 2022 | SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) ... |
| CVE-2021-32934 | HIGH | 7.5 | 0.6% | May 19, 2022 | The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not... |
| CVE-2021-26631 | HIGH | 7.5 | 1.0% | May 19, 2022 | Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now