2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30062 | HIGH | 7.5 | 0.8% | Apr 3, 2022 | On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafte... |
| CVE-2021-3847 | HIGH | 7.8 | 0.5% | Apr 1, 2022 | An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsyste... |
| CVE-2021-3461 | HIGH | 7.1 | 0.3% | Apr 1, 2022 | A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SA... |
| CVE-2021-39908 | HIGH | 7.5 | 1.2% | Apr 1, 2022 | In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and al... |
| CVE-2021-33657 | HIGH | 8.8 | 2.0% | Apr 1, 2022 | There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By craf... |
| CVE-2021-33024 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure met... |
| CVE-2021-33022 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communicati... |
| CVE-2021-33020 | HIGH | 7.5 | 0.6% | Apr 1, 2022 | Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which dimini... |
| CVE-2021-33018 | HIGH | 7.5 | 0.5% | Apr 1, 2022 | The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary r... |
| CVE-2021-32970 | HIGH | 7.5 | 1.6% | Apr 1, 2022 | Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 ... |
| CVE-2021-32968 | HIGH | 7.5 | 1.6% | Apr 1, 2022 | Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may al... |
| CVE-2021-32961 | HIGH | 7.5 | 1.2% | Apr 1, 2022 | A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting ... |
| CVE-2021-32960 | HIGH | 8.8 | 2.3% | Apr 1, 2022 | Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed con... |
| CVE-2021-32957 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and... |
| CVE-2021-32949 | HIGH | 7.5 | 1.1% | Apr 1, 2022 | An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path ... |
| CVE-2021-32945 | HIGH | 7.5 | 0.4% | Apr 1, 2022 | An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06. |
| CVE-2021-32937 | HIGH | 7.5 | 1.0% | Apr 1, 2022 | An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in ... |
| CVE-2021-28504 | HIGH | 7.5 | 0.7% | Apr 1, 2022 | On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which m... |
| CVE-2021-26624 | HIGH | 8.8 | 2.3% | Apr 1, 2022 | An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due ... |
| CVE-2021-22277 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Produc... |
| CVE-2021-35115 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon... |
| CVE-2021-35110 | HIGH | 8.8 | 0.2% | Apr 1, 2022 | Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivi... |
| CVE-2021-35106 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Sn... |
| CVE-2021-35105 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon ... |
| CVE-2021-35103 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Possible out of bound write due to improper validation of number of timer values received from firmware while syncing ti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now