2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44016 | HIGH | 7.8 | 1.6% | Feb 9, 2022 | A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S... |
| CVE-2021-44000 | HIGH | 7.8 | 1.7% | Feb 9, 2022 | A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S... |
| CVE-2021-40363 | HIGH | 7.8 | 0.2% | Feb 9, 2022 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS... |
| CVE-2021-40360 | HIGH | 8.8 | 0.7% | Feb 9, 2022 | A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS... |
| CVE-2021-37205 | HIGH | 7.5 | 1.6% | Feb 9, 2022 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200... |
| CVE-2021-37204 | HIGH | 7.5 | 2.1% | Feb 9, 2022 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller... |
| CVE-2021-37194 | HIGH | 7.5 | 0.8% | Feb 9, 2022 | A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers... |
| CVE-2021-37185 | HIGH | 7.5 | 2.0% | Feb 9, 2022 | A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200... |
| CVE-2021-46360 | HIGH | 8.8 | 9.2% | Feb 9, 2022 | Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar... |
| CVE-2021-46354 | HIGH | 7.5 | 15.6% | Feb 9, 2022 | Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vuln... |
| CVE-2021-37852 | HIGH | 7.8 | 0.6% | Feb 9, 2022 | ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attack... |
| CVE-2021-45326 | HIGH | 8.8 | 0.6% | Feb 8, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especi... |
| CVE-2021-45325 | HIGH | 7.5 | 1.0% | Feb 8, 2022 | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. |
| CVE-2021-3835 | HIGH | 8.8 | 0.7% | Feb 7, 2022 | Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more in... |
| CVE-2021-42833 | HIGH | 8.8 | 0.2% | Feb 7, 2022 | A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenti... |
| CVE-2021-25108 | HIGH | 7.1 | 0.4% | Feb 7, 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_block... |
| CVE-2021-25095 | HIGH | 7.1 | 0.5% | Feb 7, 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc... |
| CVE-2021-24879 | HIGH | 8.8 | 0.6% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any san... |
| CVE-2021-24839 | HIGH | 7.5 | 1.2% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti... |
| CVE-2021-46389 | HIGH | 7.5 | 1.2% | Feb 7, 2022 | IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by ... |
| CVE-2021-46359 | HIGH | 7.5 | 1.2% | Feb 7, 2022 | FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successf... |
| CVE-2021-43928 | HIGH | 8.8 | 1.9% | Feb 7, 2022 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending... |
| CVE-2021-39280 | HIGH | 8.8 | 2.2% | Feb 6, 2022 | Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affect... |
| CVE-2021-4154 | HIGH | 8.8 | 1.2% | Feb 4, 2022 | A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 pars... |
| CVE-2021-44206 | HIGH | 7.3 | 0.2% | Feb 4, 2022 | Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now