2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23452 | CRITICAL | 9.8 | 1.5% | Oct 20, 2021 | This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object. |
| CVE-2021-35652 | CRITICAL | 10 | 1.8% | Oct 20, 2021 | Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported v... |
| CVE-2021-35617 | CRITICAL | 9.8 | 2.0% | Oct 20, 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Suppor... |
| CVE-2021-30304 | CRITICAL | 9.1 | 0.6% | Oct 20, 2021 | Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon... |
| CVE-2021-1980 | CRITICAL | 9.1 | 0.6% | Oct 20, 2021 | Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Co... |
| CVE-2021-1977 | CRITICAL | 9.1 | 0.6% | Oct 20, 2021 | Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC respo... |
| CVE-2021-31384 | CRITICAL | 10 | 1.1% | Oct 19, 2021 | Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuratio... |
| CVE-2021-31382 | CRITICAL | 9 | 0.6% | Oct 19, 2021 | On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between t... |
| CVE-2021-31381 | CRITICAL | 9.1 | 1.1% | Oct 19, 2021 | A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remo... |
| CVE-2021-31349 | CRITICAL | 9.8 | 1.7% | Oct 19, 2021 | The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to v... |
| CVE-2021-30820 | CRITICAL | 9.8 | 2.2% | Oct 19, 2021 | A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8. A remote at... |
| CVE-2021-38478 | CRITICAL | 9.1 | 1.1% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute too... |
| CVE-2021-38474 | CRITICAL | 9.8 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for th... |
| CVE-2021-38470 | CRITICAL | 9.1 | 1.1% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to i... |
| CVE-2021-38462 | CRITICAL | 9.8 | 1.1% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This ... |
| CVE-2021-41153 | CRITICAL | 9.8 | 1.0% | Oct 18, 2021 | The evm crate is a pure Rust implementation of Ethereum Virtual Machine. In `evm` crate `< 0.31.0`, `JUMPI` opcode's con... |
| CVE-2021-23449 | CRITICAL | 10 | 3.5% | Oct 18, 2021 | This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitr... |
| CVE-2021-42576 | CRITICAL | 9.8 | 1.5% | Oct 18, 2021 | The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce ... |
| CVE-2021-42575 | CRITICAL | 9.8 | 2.8% | Oct 18, 2021 | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, an... |
| CVE-2021-38389 | CRITICAL | 9.8 | 10.4% | Oct 18, 2021 | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker... |
| CVE-2021-33023 | CRITICAL | 9.8 | 2.2% | Oct 18, 2021 | Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker ... |
| CVE-2021-22961 | CRITICAL | 9.8 | 1.7% | Oct 18, 2021 | A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary co... |
| CVE-2021-38297 | CRITICAL | 9.8 | 10.3% | Oct 18, 2021 | Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM... |
| CVE-2021-27561 | CRITICAL | 9.8 | 82.5% | Oct 15, 2021 | Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, ... |
| CVE-2021-40997 | CRITICAL | 9.8 | 1.7% | Oct 15, 2021 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Poli... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now