2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25268 | HIGH | 8.4 | 0.9% | May 5, 2022 | Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Fire... |
| CVE-2021-25267 | HIGH | 8.4 | 1.1% | May 5, 2022 | Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall old... |
| CVE-2021-44052 | HIGH | 8.1 | 1.4% | May 5, 2022 | An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device ... |
| CVE-2021-44051 | HIGH | 8.8 | 1.6% | May 5, 2022 | A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploite... |
| CVE-2021-43547 | HIGH | 8.2 | 2.4% | May 5, 2022 | TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially... |
| CVE-2021-38447 | HIGH | 7.5 | 2.0% | May 5, 2022 | OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de... |
| CVE-2021-38433 | HIGH | 7.8 | 0.5% | May 5, 2022 | RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 vulnerable to a stack-based buffer overflow, ... |
| CVE-2021-38427 | HIGH | 7.8 | 0.5% | May 5, 2022 | RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overf... |
| CVE-2021-42183 | HIGH | 7.5 | 4.5% | May 5, 2022 | MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. |
| CVE-2021-41020 | HIGH | 8.8 | 0.6% | May 4, 2022 | An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated,... |
| CVE-2021-20051 | HIGH | 7.8 | 0.7% | May 4, 2022 | SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijac... |
| CVE-2021-32010 | HIGH | 8.1 | 0.2% | May 4, 2022 | Inadequate Encryption Strength vulnerability in TLS stack of Secomea SiteManager, LinkManager, GateManager may facilitat... |
| CVE-2021-42192 | HIGH | 8.8 | 9.5% | May 4, 2022 | Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to pri... |
| CVE-2021-43164 | HIGH | 8.8 | 34.9% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43162 | HIGH | 8.8 | 1.8% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43161 | HIGH | 8.8 | 1.8% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43160 | HIGH | 8.8 | 1.8% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-43159 | HIGH | 8.8 | 1.9% | May 4, 2022 | A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191... |
| CVE-2021-29854 | HIGH | 7.2 | 1.0% | May 3, 2022 | IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of... |
| CVE-2021-46440 | HIGH | 7.5 | 2.2% | May 3, 2022 | Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.... |
| CVE-2021-22573 | HIGH | 7.3 | 0.3% | May 3, 2022 | The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sur... |
| CVE-2021-22556 | HIGH | 7.8 | 0.2% | May 3, 2022 | The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache i... |
| CVE-2021-42165 | HIGH | 8.8 | 13.1% | May 3, 2022 | MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing c... |
| CVE-2021-42218 | HIGH | 7.5 | 1.0% | May 3, 2022 | OMPL v1.5.2 contains a memory leak in VFRRT.cpp |
| CVE-2021-41959 | HIGH | 7.5 | 1.1% | May 3, 2022 | JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now