2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36312 | CRITICAL | 9.1 | 1.0% | Nov 23, 2021 | Dell EMC CloudLink 7.1 and all prior versions contain a Hard-coded Password Vulnerability. A remote high privileged atta... |
| CVE-2021-37022 | CRITICAL | 9.8 | 0.9% | Nov 23, 2021 | There is a Heap-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability w... |
| CVE-2021-37016 | CRITICAL | 9.1 | 0.8% | Nov 23, 2021 | There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will caus... |
| CVE-2021-44144 | CRITICAL | 9.1 | 1.1% | Nov 22, 2021 | Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date... |
| CVE-2021-44143 | CRITICAL | 9.8 | 3.7% | Nov 22, 2021 | A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP ... |
| CVE-2021-23732 | CRITICAL | 9 | 1.8% | Nov 22, 2021 | This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least b... |
| CVE-2021-3943 | CRITICAL | 9.8 | 2.4% | Nov 22, 2021 | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A... |
| CVE-2021-26614 | CRITICAL | 9.8 | 2.5% | Nov 22, 2021 | ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the e... |
| CVE-2021-44079 | CRITICAL | 9.8 | 3.3% | Nov 22, 2021 | In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl comman... |
| CVE-2021-36320 | CRITICAL | 9.8 | 1.2% | Nov 20, 2021 | Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote una... |
| CVE-2021-36308 | CRITICAL | 9.8 | 3.2% | Nov 20, 2021 | Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an authentication bypass vu... |
| CVE-2021-36306 | CRITICAL | 9.8 | 3.6% | Nov 20, 2021 | Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerabili... |
| CVE-2021-41280 | CRITICAL | 9.8 | 3.4% | Nov 19, 2021 | Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is pos... |
| CVE-2021-23433 | CRITICAL | 9.8 | 1.6% | Nov 19, 2021 | The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in ... |
| CVE-2021-40391 | CRITICAL | 9.8 | 2.9% | Nov 19, 2021 | An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (co... |
| CVE-2021-22028 | CRITICAL | 9.1 | 2.4% | Nov 19, 2021 | In versions of Greenplum database prior to 5.28.6 and 6.14.0, greenplum database contains a file path traversal vulnerab... |
| CVE-2021-37592 | CRITICAL | 9.8 | 1.6% | Nov 19, 2021 | Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a c... |
| CVE-2021-41435 | CRITICAL | 9.8 | 6.0% | Nov 19, 2021 | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-A... |
| CVE-2021-39233 | CRITICAL | 9.1 | 2.3% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authori... |
| CVE-2021-39231 | CRITICAL | 9.1 | 2.3% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, ... |
| CVE-2021-36372 | CRITICAL | 9.8 | 2.4% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can... |
| CVE-2021-42338 | CRITICAL | 9.8 | 5.6% | Nov 19, 2021 | 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to byp... |
| CVE-2021-44026 | CRITICAL | 9.8 | 42.9% | Nov 19, 2021 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
| CVE-2021-27023 | CRITICAL | 9.8 | 1.3% | Nov 18, 2021 | A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTT... |
| CVE-2021-43996 | CRITICAL | 9.8 | 1.7% | Nov 17, 2021 | The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can l... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now