2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37064 | CRITICAL | 9.1 | 0.8% | Dec 7, 2021 | There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exp... |
| CVE-2021-37063 | CRITICAL | 9.8 | 0.7% | Dec 7, 2021 | There is a Cryptographic Issues vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lea... |
| CVE-2021-37062 | CRITICAL | 9.1 | 0.7% | Dec 7, 2021 | There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnera... |
| CVE-2021-37059 | CRITICAL | 9.8 | 0.7% | Dec 7, 2021 | There is a Weaknesses Introduced During Design |
| CVE-2021-37021 | CRITICAL | 9.1 | 0.8% | Dec 7, 2021 | There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ... |
| CVE-2021-37020 | CRITICAL | 9.1 | 0.8% | Dec 7, 2021 | There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ... |
| CVE-2021-37011 | CRITICAL | 9.1 | 0.9% | Dec 7, 2021 | There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability ... |
| CVE-2021-37042 | CRITICAL | 9.1 | 0.7% | Dec 7, 2021 | There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may c... |
| CVE-2021-37041 | CRITICAL | 9.1 | 0.7% | Dec 7, 2021 | There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may c... |
| CVE-2021-42128 | CRITICAL | 9.8 | 4.5% | Dec 7, 2021 | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privil... |
| CVE-2021-42127 | CRITICAL | 9.8 | 68.0% | Dec 7, 2021 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows ... |
| CVE-2021-29114 | CRITICAL | 9.8 | 1.0% | Dec 7, 2021 | A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthe... |
| CVE-2021-44685 | CRITICAL | 9.8 | 3.5% | Dec 7, 2021 | Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verifi... |
| CVE-2021-44684 | CRITICAL | 9.8 | 2.6% | Dec 7, 2021 | naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenat... |
| CVE-2021-44682 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | An issue (6 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault applicati... |
| CVE-2021-44681 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | An issue (5 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault applicati... |
| CVE-2021-44680 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | An issue (4 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault applicati... |
| CVE-2021-44679 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | An issue (3 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault applicati... |
| CVE-2021-44678 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | An issue (2 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault applicati... |
| CVE-2021-44677 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | An issue (1 of 6) was discovered in Veritas Enterprise Vault through 14.1.2. On start-up, the Enterprise Vault applicati... |
| CVE-2021-31632 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the Use... |
| CVE-2021-40091 | CRITICAL | 9.8 | 1.1% | Dec 6, 2021 | An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. |
| CVE-2021-36567 | CRITICAL | 9.8 | 2.4% | Dec 6, 2021 | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Stor... |
| CVE-2021-36564 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cach... |
| CVE-2021-43936 | CRITICAL | 9.8 | 35.8% | Dec 6, 2021 | The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automa... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now