2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1981 | CRITICAL | 9.1 | 0.6% | Nov 12, 2021 | Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snap... |
| CVE-2021-1975 | CRITICAL | 9.8 | 0.8% | Nov 12, 2021 | Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdra... |
| CVE-2021-42775 | CRITICAL | 9.1 | 1.0% | Nov 12, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-42774 | CRITICAL | 9.8 | 2.4% | Nov 12, 2021 | Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly... |
| CVE-2021-34422 | CRITICAL | 9 | 1.3% | Nov 11, 2021 | The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a ... |
| CVE-2021-3907 | CRITICAL | 9.8 | 4.1% | Nov 11, 2021 | OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://... |
| CVE-2021-43350 | CRITICAL | 9.8 | 4.4% | Nov 11, 2021 | An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the P... |
| CVE-2021-42847 | CRITICAL | 9.8 | 70.3% | Nov 11, 2021 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. |
| CVE-2021-42002 | CRITICAL | 9.8 | 7.2% | Nov 11, 2021 | Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code exec... |
| CVE-2021-41833 | CRITICAL | 9.8 | 7.8% | Nov 11, 2021 | Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. |
| CVE-2021-41081 | CRITICAL | 9.8 | 69.2% | Nov 11, 2021 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search... |
| CVE-2021-41080 | CRITICAL | 9.8 | 4.2% | Nov 11, 2021 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details sea... |
| CVE-2021-43573 | CRITICAL | 9.8 | 1.1% | Nov 11, 2021 | A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processin... |
| CVE-2021-33816 | CRITICAL | 9.8 | 3.8% | Nov 10, 2021 | The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mecha... |
| CVE-2021-40520 | CRITICAL | 9.8 | 1.1% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials. |
| CVE-2021-3064 | CRITICAL | 9.8 | 19.1% | Nov 10, 2021 | A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables ... |
| CVE-2021-40521 | CRITICAL | 9.8 | 4.3% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution. |
| CVE-2021-40519 | CRITICAL | 10 | 1.1% | Nov 10, 2021 | Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials. |
| CVE-2021-43523 | CRITICAL | 9.6 | 3.3% | Nov 10, 2021 | In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers ... |
| CVE-2021-43136 | CRITICAL | 9.8 | 15.7% | Nov 10, 2021 | An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain... |
| CVE-2021-26443 | CRITICAL | 9 | 1.6% | Nov 10, 2021 | Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
| CVE-2021-43572 | CRITICAL | 9.8 | 1.2% | Nov 9, 2021 | The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to ... |
| CVE-2021-43571 | CRITICAL | 9.8 | 1.0% | Nov 9, 2021 | The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-... |
| CVE-2021-43570 | CRITICAL | 9.8 | 1.0% | Nov 9, 2021 | The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zer... |
| CVE-2021-43569 | CRITICAL | 9.8 | 1.0% | Nov 9, 2021 | The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-z... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now