2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39299 | HIGH | 8.8 | 0.4% | Feb 16, 2022 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation o... |
| CVE-2021-39298 | HIGH | 8.8 | 0.4% | Feb 16, 2022 | A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileg... |
| CVE-2021-39297 | HIGH | 8.8 | 0.4% | Feb 16, 2022 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation o... |
| CVE-2021-22050 | HIGH | 7.5 | 2.3% | Feb 16, 2022 | ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to E... |
| CVE-2021-22043 | HIGH | 7.5 | 1.0% | Feb 16, 2022 | VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handl... |
| CVE-2021-22042 | HIGH | 7.8 | 0.3% | Feb 16, 2022 | VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A... |
| CVE-2021-21958 | HIGH | 7.8 | 1.0% | Feb 16, 2022 | A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2... |
| CVE-2021-26726 | HIGH | 8.8 | 1.1% | Feb 16, 2022 | A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to e... |
| CVE-2021-45391 | HIGH | 7.5 | 1.8% | Feb 16, 2022 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/set... |
| CVE-2021-35380 | HIGH | 7.5 | 39.0% | Feb 15, 2022 | A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthe... |
| CVE-2021-42714 | HIGH | 7.8 | 0.4% | Feb 15, 2022 | Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permiss... |
| CVE-2021-42713 | HIGH | 7.8 | 0.3% | Feb 15, 2022 | Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permiss... |
| CVE-2021-43050 | HIGH | 7.8 | 0.2% | Feb 15, 2022 | The Auth Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitabl... |
| CVE-2021-43734 | HIGH | 7.5 | 10.7% | Feb 15, 2022 | kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file l... |
| CVE-2021-42712 | HIGH | 7.8 | 0.3% | Feb 15, 2022 | Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. |
| CVE-2021-41552 | HIGH | 8.8 | 0.7% | Feb 15, 2022 | CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. |
| CVE-2021-43940 | HIGH | 7.8 | 0.3% | Feb 15, 2022 | Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated... |
| CVE-2021-46462 | HIGH | 7.5 | 1.7% | Feb 14, 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /sr... |
| CVE-2021-45348 | HIGH | 7.5 | 0.9% | Feb 14, 2022 | An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv paramete... |
| CVE-2021-45347 | HIGH | 7.5 | 1.1% | Feb 14, 2022 | An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by chan... |
| CVE-2021-45392 | HIGH | 7.5 | 12.3% | Feb 14, 2022 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/s... |
| CVE-2021-46371 | HIGH | 7.5 | 4.4% | Feb 14, 2022 | antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the... |
| CVE-2021-45421 | HIGH | 7.5 | 1.6% | Feb 14, 2022 | Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can ... |
| CVE-2021-45444 | HIGH | 7.8 | 2.0% | Feb 14, 2022 | In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demon... |
| CVE-2021-4102 | HIGH | 8.8 | 7.8% | Feb 11, 2022 | Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corru... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now