2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37599 | CRITICAL | 9.8 | 3.1% | Aug 12, 2021 | The exporter/Login.aspx login form in the Exporter in Nuance Winscribe Dictation 4.1.0.99 is vulnerable to SQL injection... |
| CVE-2021-33199 | CRITICAL | 9.8 | 1.4% | Aug 12, 2021 | In Expression Engine before 6.0.3, addonIcon in Addons/file/mod.file.php relies on the untrusted input value of input->g... |
| CVE-2021-26432 | CRITICAL | 9.8 | 10.3% | Aug 12, 2021 | Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability |
| CVE-2021-26424 | CRITICAL | 9.9 | 58.9% | Aug 12, 2021 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2021-38606 | CRITICAL | 9.8 | 1.2% | Aug 12, 2021 | reNgine through 0.5 relies on a predictable directory name. |
| CVE-2021-20509 | CRITICAL | 9.8 | 1.7% | Aug 12, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is potentially vulnerable to CSV Injection. A remote attacker could execute ... |
| CVE-2021-20314 | CRITICAL | 9.8 | 2.8% | Aug 12, 2021 | Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service ... |
| CVE-2021-37222 | CRITICAL | 9.8 | 2.5% | Aug 12, 2021 | Parsers in the open source project RCDCAP before 1.0.5 allow remote attackers to execute arbitrary code or cause a denia... |
| CVE-2021-38574 | CRITICAL | 9.8 | 1.0% | Aug 11, 2021 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows SQL Injection via crafted data at the en... |
| CVE-2021-38573 | CRITICAL | 9.8 | 1.1% | Aug 11, 2021 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because a Com... |
| CVE-2021-38572 | CRITICAL | 9.8 | 1.1% | Aug 11, 2021 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the e... |
| CVE-2021-38570 | CRITICAL | 9.1 | 1.2% | Aug 11, 2021 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows attackers to delete arbitrary files (dur... |
| CVE-2021-38568 | CRITICAL | 9.8 | 1.1% | Aug 11, 2021 | An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a... |
| CVE-2021-38564 | CRITICAL | 9.1 | 1.1% | Aug 11, 2021 | An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows an out-of-bounds read ... |
| CVE-2021-38563 | CRITICAL | 9.8 | 1.1% | Aug 11, 2021 | An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in whic... |
| CVE-2021-33794 | CRITICAL | 9.1 | 1.1% | Aug 11, 2021 | Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 allow information disclosure or an application crash after misha... |
| CVE-2021-33793 | CRITICAL | 9.8 | 1.1% | Aug 11, 2021 | Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is... |
| CVE-2021-23421 | CRITICAL | 9.8 | 1.1% | Aug 11, 2021 | All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function. |
| CVE-2021-20418 | CRITICAL | 9.8 | 1.0% | Aug 11, 2021 | IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier fo... |
| CVE-2021-23420 | CRITICAL | 9.8 | 2.7% | Aug 11, 2021 | This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be... |
| CVE-2021-38530 | CRITICAL | 9.8 | 2.2% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.... |
| CVE-2021-38529 | CRITICAL | 9.8 | 1.7% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.... |
| CVE-2021-38528 | CRITICAL | 9.8 | 2.0% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.... |
| CVE-2021-38527 | CRITICAL | 9.8 | 1.7% | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.... |
| CVE-2021-38516 | CRITICAL | 9.8 | 1.3% | Aug 11, 2021 | Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now