2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25449 | CRITICAL | 9.8 | 0.4% | Sep 9, 2021 | An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers ... |
| CVE-2021-39296 | CRITICAL | 10 | 2.9% | Sep 9, 2021 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system. |
| CVE-2021-28913 | CRITICAL | 9.8 | 1.8% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to v... |
| CVE-2021-28911 | CRITICAL | 9.8 | 1.6% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains s... |
| CVE-2021-28909 | CRITICAL | 9.8 | 1.3% | Sep 9, 2021 | BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login ser... |
| CVE-2021-38727 | CRITICAL | 9.8 | 1.6% | Sep 9, 2021 | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items |
| CVE-2021-38540 | CRITICAL | 9.8 | 80.9% | Sep 9, 2021 | The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticate... |
| CVE-2021-28495 | CRITICAL | 9.8 | 0.9% | Sep 9, 2021 | In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio... |
| CVE-2021-26608 | CRITICAL | 9.8 | 0.6% | Sep 9, 2021 | An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware Activ... |
| CVE-2021-38408 | CRITICAL | 9.8 | 11.6% | Sep 9, 2021 | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper va... |
| CVE-2021-37579 | CRITICAL | 9.8 | 6.5% | Sep 9, 2021 | The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the con... |
| CVE-2021-36161 | CRITICAL | 9.8 | 2.4% | Sep 9, 2021 | Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for ... |
| CVE-2021-1946 | CRITICAL | 9.8 | 0.8% | Sep 9, 2021 | Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snap... |
| CVE-2021-1933 | CRITICAL | 9.8 | 0.8% | Sep 9, 2021 | UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compu... |
| CVE-2021-32835 | CRITICAL | 9.9 | 4.4% | Sep 9, 2021 | Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti... |
| CVE-2021-32834 | CRITICAL | 9.9 | 0.9% | Sep 9, 2021 | Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti... |
| CVE-2021-40818 | CRITICAL | 9.8 | 1.4% | Sep 8, 2021 | scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webaut... |
| CVE-2021-40814 | CRITICAL | 9.8 | 1.0% | Sep 8, 2021 | The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection. |
| CVE-2021-36440 | CRITICAL | 9.8 | 4.7% | Sep 8, 2021 | Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' paramete... |
| CVE-2021-30690 | CRITICAL | 9.8 | 1.3% | Sep 8, 2021 | Multiple issues in apache were addressed by updating apache to version 2.4.46. This issue is fixed in Security Update 20... |
| CVE-2021-30678 | CRITICAL | 9.8 | 3.2% | Sep 8, 2021 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2... |
| CVE-2021-30655 | CRITICAL | 9.8 | 2.2% | Sep 8, 2021 | An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, ... |
| CVE-2021-1882 | CRITICAL | 9.8 | 1.6% | Sep 8, 2021 | A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catali... |
| CVE-2021-1864 | CRITICAL | 9.8 | 2.1% | Sep 8, 2021 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, w... |
| CVE-2021-1834 | CRITICAL | 9.8 | 2.9% | Sep 8, 2021 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Sec... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now