2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42651 | HIGH | 8.8 | 1.5% | May 11, 2022 | A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated ... |
| CVE-2021-37851 | HIGH | 7.8 | 0.2% | May 11, 2022 | Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair featu... |
| CVE-2021-34606 | HIGH | 7.3 | 0.4% | May 11, 2022 | A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, l... |
| CVE-2021-34605 | HIGH | 7.3 | 2.3% | May 11, 2022 | A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitra... |
| CVE-2021-3254 | HIGH | 7.5 | 1.7% | May 11, 2022 | Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap. |
| CVE-2021-39738 | HIGH | 7.8 | 0.1% | May 10, 2022 | In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This co... |
| CVE-2021-46771 | HIGH | 7.8 | 0.3% | May 10, 2022 | Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrar... |
| CVE-2021-43010 | HIGH | 7.5 | 1.0% | May 10, 2022 | In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensit... |
| CVE-2021-26408 | HIGH | 7.1 | 0.3% | May 10, 2022 | Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potent... |
| CVE-2021-26370 | HIGH | 7.1 | 0.2% | May 10, 2022 | Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious... |
| CVE-2021-26353 | HIGH | 7.8 | 0.3% | May 10, 2022 | Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partiall... |
| CVE-2021-26332 | HIGH | 7.1 | 0.2% | May 10, 2022 | Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availabili... |
| CVE-2021-26324 | HIGH | 7.8 | 0.3% | May 10, 2022 | A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs. |
| CVE-2021-41545 | HIGH | 7.5 | 0.9% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2021-20479 | HIGH | 7.5 | 0.6% | May 9, 2022 | IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2021-27767 | HIGH | 7.8 | 0.2% | May 6, 2022 | The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that c... |
| CVE-2021-27766 | HIGH | 7.8 | 0.2% | May 6, 2022 | The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that co... |
| CVE-2021-27765 | HIGH | 7.8 | 0.3% | May 6, 2022 | The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability tha... |
| CVE-2021-27761 | HIGH | 7.5 | 0.3% | May 6, 2022 | Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks |
| CVE-2021-42743 | HIGH | 7.8 | 0.2% | May 6, 2022 | A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Sp... |
| CVE-2021-31559 | HIGH | 7.5 | 0.8% | May 6, 2022 | A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexe... |
| CVE-2021-26253 | HIGH | 8.1 | 0.7% | May 6, 2022 | A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in ... |
| CVE-2021-39023 | HIGH | 7.5 | 0.8% | May 6, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a ... |
| CVE-2021-25746 | HIGH | 7.1 | 1.3% | May 6, 2022 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadat... |
| CVE-2021-25745 | HIGH | 8.1 | 1.1% | May 6, 2022 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now