2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38266 | HIGH | 7.5 | 2.2% | Mar 2, 2022 | The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix p... |
| CVE-2021-23206 | HIGH | 7.8 | 1.4% | Mar 2, 2022 | A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to exe... |
| CVE-2021-23192 | HIGH | 7.5 | 1.9% | Mar 2, 2022 | A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, ... |
| CVE-2021-23191 | HIGH | 7.8 | 1.1% | Mar 2, 2022 | A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() i... |
| CVE-2021-23180 | HIGH | 7.8 | 1.3% | Mar 2, 2022 | A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to ex... |
| CVE-2021-41002 | HIGH | 8.1 | 0.9% | Mar 2, 2022 | Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aru... |
| CVE-2021-41001 | HIGH | 8.8 | 2.5% | Mar 2, 2022 | An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Arub... |
| CVE-2021-41000 | HIGH | 8.8 | 2.4% | Mar 2, 2022 | Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aru... |
| CVE-2021-41652 | HIGH | 7.5 | 1.1% | Mar 1, 2022 | Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database. |
| CVE-2021-41282 | HIGH | 8.8 | 87.1% | Mar 1, 2022 | diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo... |
| CVE-2021-43077 | HIGH | 8.8 | 0.8% | Mar 1, 2022 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-43075 | HIGH | 8.8 | 1.6% | Mar 1, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio... |
| CVE-2021-36171 | HIGH | 8.1 | 1.1% | Mar 1, 2022 | The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6... |
| CVE-2021-44238 | HIGH | 7.2 | 1.8% | Mar 1, 2022 | AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php, |
| CVE-2021-43619 | HIGH | 7.8 | 0.4% | Mar 1, 2022 | Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a... |
| CVE-2021-42951 | HIGH | 8.8 | 1.7% | Mar 1, 2022 | A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. User... |
| CVE-2021-41112 | HIGH | 8.1 | 0.7% | Feb 28, 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3... |
| CVE-2021-44342 | HIGH | 7.8 | 0.7% | Feb 28, 2022 | David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok... |
| CVE-2021-44331 | HIGH | 7.8 | 0.9% | Feb 28, 2022 | ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise(). |
| CVE-2021-44340 | HIGH | 7.8 | 0.7% | Feb 28, 2022 | David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats pr... |
| CVE-2021-44339 | HIGH | 7.8 | 0.7% | Feb 28, 2022 | David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats projec... |
| CVE-2021-44334 | HIGH | 7.8 | 0.7% | Feb 28, 2022 | David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats projec... |
| CVE-2021-24864 | HIGH | 8.8 | 1.2% | Feb 28, 2022 | The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S... |
| CVE-2021-24823 | HIGH | 8.1 | 0.5% | Feb 28, 2022 | The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php... |
| CVE-2021-24803 | HIGH | 8.8 | 0.6% | Feb 28, 2022 | The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now