2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24704 | HIGH | 8.8 | 0.6% | Feb 28, 2022 | In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" per... |
| CVE-2021-3967 | HIGH | 8.8 | 0.8% | Feb 26, 2022 | Improper Access Control in GitHub repository zulip/zulip prior to 4.10. |
| CVE-2021-44132 | HIGH | 7.8 | 3.1% | Feb 25, 2022 | A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers t... |
| CVE-2021-40043 | HIGH | 7.8 | 0.4% | Feb 25, 2022 | The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00)... |
| CVE-2021-37027 | HIGH | 7.5 | 0.6% | Feb 25, 2022 | There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service integrity. |
| CVE-2021-22489 | HIGH | 7.5 | 0.6% | Feb 25, 2022 | There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service availabili... |
| CVE-2021-22437 | HIGH | 7 | 0.2% | Feb 25, 2022 | There is a software integer overflow leading to a TOCTOU condition in smartphones. Successful exploitation of this vulne... |
| CVE-2021-22395 | HIGH | 7.5 | 0.7% | Feb 25, 2022 | There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service... |
| CVE-2021-22319 | HIGH | 7.5 | 0.7% | Feb 25, 2022 | There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause ... |
| CVE-2021-39364 | HIGH | 7.5 | 1.0% | Feb 24, 2022 | Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP ... |
| CVE-2021-29220 | HIGH | 7.2 | 2.0% | Feb 24, 2022 | Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.... |
| CVE-2021-44664 | HIGH | 8.8 | 12.8% | Feb 24, 2022 | An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupl... |
| CVE-2021-4021 | HIGH | 7.5 | 1.0% | Feb 24, 2022 | A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled w... |
| CVE-2021-44531 | HIGH | 7.4 | 8.4% | Feb 24, 2022 | Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN t... |
| CVE-2021-3610 | HIGH | 7.5 | 2.7% | Feb 24, 2022 | A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in... |
| CVE-2021-26252 | HIGH | 7.8 | 0.9% | Feb 24, 2022 | A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute a... |
| CVE-2021-4030 | HIGH | 8.8 | 0.4% | Feb 24, 2022 | A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker ... |
| CVE-2021-4029 | HIGH | 8.8 | 0.8% | Feb 24, 2022 | A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execut... |
| CVE-2021-45746 | HIGH | 7.5 | 1.5% | Feb 24, 2022 | A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackag... |
| CVE-2021-44967 | HIGH | 8.8 | 12.7% | Feb 24, 2022 | A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which... |
| CVE-2021-25636 | HIGH | 7.5 | 1.0% | Feb 24, 2022 | LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt... |
| CVE-2021-43826 | HIGH | 7.5 | 1.0% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a ... |
| CVE-2021-43825 | HIGH | 7.5 | 0.9% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. Sending a locally generated resp... |
| CVE-2021-43824 | HIGH | 7.5 | 1.0% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted r... |
| CVE-2021-46699 | HIGH | 7.8 | 1.4% | Feb 22, 2022 | A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains a stack... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now