2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41938 | HIGH | 7.2 | 1.0% | May 19, 2022 | An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulne... |
| CVE-2021-42704 | HIGH | 7.8 | 1.3% | May 18, 2022 | Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code. |
| CVE-2021-42852 | HIGH | 8 | 0.8% | May 18, 2022 | A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authent... |
| CVE-2021-42850 | HIGH | 7.8 | 0.2% | May 18, 2022 | A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud S... |
| CVE-2021-3969 | HIGH | 7 | 1.8% | May 18, 2022 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System I... |
| CVE-2021-3922 | HIGH | 7 | 1.8% | May 18, 2022 | A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,... |
| CVE-2021-38872 | HIGH | 7.5 | 1.4% | May 17, 2022 | IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a re... |
| CVE-2021-42643 | HIGH | 8.8 | 1.6% | May 17, 2022 | cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script f... |
| CVE-2021-33025 | HIGH | 7.8 | 0.3% | May 16, 2022 | xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges. |
| CVE-2021-23267 | HIGH | 8.8 | 0.8% | May 16, 2022 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat... |
| CVE-2021-25119 | HIGH | 7.2 | 1.4% | May 16, 2022 | The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating t... |
| CVE-2021-42870 | HIGH | 7.5 | 1.0% | May 16, 2022 | ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request. |
| CVE-2021-41965 | HIGH | 8.8 | 1.1% | May 15, 2022 | A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue ... |
| CVE-2021-33013 | HIGH | 7.5 | 0.8% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. |
| CVE-2021-33009 | HIGH | 7.5 | 1.1% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file s... |
| CVE-2021-33005 | HIGH | 7.5 | 1.4% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary ... |
| CVE-2021-27505 | HIGH | 7.5 | 1.0% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing informa... |
| CVE-2021-46789 | HIGH | 7.5 | 0.6% | May 13, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability. |
| CVE-2021-46788 | HIGH | 7.5 | 0.5% | May 13, 2022 | Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability ma... |
| CVE-2021-46787 | HIGH | 7.5 | 0.7% | May 13, 2022 | The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may caus... |
| CVE-2021-22275 | HIGH | 8.6 | 0.9% | May 13, 2022 | Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to st... |
| CVE-2021-42969 | HIGH | 8.8 | 1.8% | May 13, 2022 | Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a ... |
| CVE-2021-27777 | HIGH | 7.5 | 0.8% | May 12, 2022 | XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input... |
| CVE-2021-27771 | HIGH | 7.6 | 0.7% | May 12, 2022 | User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. W... |
| CVE-2021-27770 | HIGH | 8.8 | 0.7% | May 12, 2022 | The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then reque... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now