2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26620 | HIGH | 7.5 | 1.3% | Mar 25, 2022 | An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attack... |
| CVE-2021-43091 | HIGH | 7.5 | 1.4% | Mar 25, 2022 | An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form. |
| CVE-2021-43666 | HIGH | 7.5 | 2.1% | Mar 24, 2022 | A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an... |
| CVE-2021-44226 | HIGH | 7.3 | 0.9% | Mar 23, 2022 | Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Servi... |
| CVE-2021-28278 | HIGH | 7.8 | 0.9% | Mar 23, 2022 | A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c... |
| CVE-2021-28277 | HIGH | 7.8 | 0.9% | Mar 23, 2022 | A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUn... |
| CVE-2021-28276 | HIGH | 7.5 | 1.1% | Mar 23, 2022 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir ... |
| CVE-2021-4197 | HIGH | 7.8 | 0.5% | Mar 23, 2022 | An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found i... |
| CVE-2021-4156 | HIGH | 7.1 | 1.8% | Mar 23, 2022 | An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a speci... |
| CVE-2021-3748 | HIGH | 7.5 | 0.5% | Mar 23, 2022 | A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address ... |
| CVE-2021-3618 | HIGH | 7.4 | 2.0% | Mar 23, 2022 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocol... |
| CVE-2021-3589 | HIGH | 8 | 1.0% | Mar 23, 2022 | An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run... |
| CVE-2021-27475 | HIGH | 8.6 | 2.8% | Mar 23, 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserializ... |
| CVE-2021-27474 | HIGH | 7.5 | 1.5% | Mar 23, 2022 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS ... |
| CVE-2021-27473 | HIGH | 8.2 | 0.8% | Mar 23, 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccw... |
| CVE-2021-27471 | HIGH | 8.6 | 2.7% | Mar 23, 2022 | The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may all... |
| CVE-2021-27422 | HIGH | 7.5 | 0.6% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sens... |
| CVE-2021-38772 | HIGH | 7.5 | 1.2% | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBi... |
| CVE-2021-46064 | HIGH | 7.8 | 1.4% | Mar 23, 2022 | IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). T... |
| CVE-2021-44139 | HIGH | 7.5 | 6.5% | Mar 23, 2022 | Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). |
| CVE-2021-43738 | HIGH | 8.8 | 0.5% | Mar 23, 2022 | An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrat... |
| CVE-2021-44759 | HIGH | 8.1 | 1.5% | Mar 23, 2022 | Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a m... |
| CVE-2021-44040 | HIGH | 7.5 | 1.9% | Mar 23, 2022 | Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send inva... |
| CVE-2021-45757 | HIGH | 7.5 | 1.8% | Mar 23, 2022 | ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (Do... |
| CVE-2021-45810 | HIGH | 7.5 | 0.8% | Mar 22, 2022 | GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService thro... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now