2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42532 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42531 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42530 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-42529 | HIGH | 7.8 | 3.6% | May 2, 2022 | XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res... |
| CVE-2021-3750 | HIGH | 8.2 | 0.5% | May 2, 2022 | A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointe... |
| CVE-2021-25002 | HIGH | 7.5 | 1.4% | May 2, 2022 | The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which co... |
| CVE-2021-46790 | HIGH | 7.8 | 0.5% | May 2, 2022 | ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream positi... |
| CVE-2021-36784 | HIGH | 7.2 | 0.8% | May 2, 2022 | A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to... |
| CVE-2021-36778 | HIGH | 7.5 | 0.7% | May 2, 2022 | A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather cred... |
| CVE-2021-40822 | HIGH | 7.5 | 18.9% | May 2, 2022 | GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. |
| CVE-2021-4207 | HIGH | 8.2 | 0.4% | Apr 29, 2022 | A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.... |
| CVE-2021-4206 | HIGH | 8.2 | 0.8% | Apr 29, 2022 | A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lea... |
| CVE-2021-36207 | HIGH | 8.8 | 0.9% | Apr 29, 2022 | Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow ... |
| CVE-2021-43937 | HIGH | 8.8 | 0.3% | Apr 29, 2022 | Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, c... |
| CVE-2021-39082 | HIGH | 7.5 | 0.6% | Apr 29, 2022 | IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2021-44595 | HIGH | 8.8 | 21.0% | Apr 29, 2022 | Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m... |
| CVE-2021-41942 | HIGH | 7.5 | 1.1% | Apr 29, 2022 | The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sens... |
| CVE-2021-43939 | HIGH | 8.8 | 0.6% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by i... |
| CVE-2021-33436 | HIGH | 7.3 | 0.3% | Apr 28, 2022 | NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe D... |
| CVE-2021-3523 | HIGH | 7.5 | 0.8% | Apr 27, 2022 | A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. T... |
| CVE-2021-38919 | HIGH | 7.5 | 1.0% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-For... |
| CVE-2021-38878 | HIGH | 7.5 | 1.1% | Apr 27, 2022 | IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity au... |
| CVE-2021-34602 | HIGH | 8.8 | 1.3% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate... |
| CVE-2021-34592 | HIGH | 8.8 | 1.3% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate... |
| CVE-2021-34591 | HIGH | 7.8 | 0.2% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacke... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now