2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44205 | HIGH | 7.3 | 0.2% | Feb 4, 2022 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2021-44204 | HIGH | 7.8 | 0.2% | Feb 4, 2022 | Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Ac... |
| CVE-2021-40420 | HIGH | 8.8 | 4.4% | Feb 4, 2022 | A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. A s... |
| CVE-2021-40401 | HIGH | 8.6 | 1.2% | Feb 4, 2022 | A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and d... |
| CVE-2021-38960 | HIGH | 7.5 | 1.0% | Feb 4, 2022 | IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID:... |
| CVE-2021-32036 | HIGH | 7.1 | 1.0% | Feb 4, 2022 | An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at... |
| CVE-2021-29219 | HIGH | 7.8 | 0.2% | Feb 4, 2022 | A potential local buffer overflow vulnerability has been identified in HPE FlexNetwork 5130 EL Switch Series version: Pr... |
| CVE-2021-22288 | HIGH | 7.5 | 1.0% | Feb 4, 2022 | Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of ... |
| CVE-2021-22286 | HIGH | 7.5 | 1.0% | Feb 4, 2022 | Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of ... |
| CVE-2021-22285 | HIGH | 7.5 | 1.0% | Feb 4, 2022 | Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the A... |
| CVE-2021-22284 | HIGH | 8.8 | 0.8% | Feb 4, 2022 | Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to exec... |
| CVE-2021-21970 | HIGH | 8.1 | 0.9% | Feb 4, 2022 | An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConn... |
| CVE-2021-21969 | HIGH | 8.1 | 0.9% | Feb 4, 2022 | An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConn... |
| CVE-2021-21968 | HIGH | 8.3 | 0.9% | Feb 4, 2022 | A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34... |
| CVE-2021-21964 | HIGH | 7.4 | 0.7% | Feb 4, 2022 | A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect ... |
| CVE-2021-21962 | HIGH | 8.1 | 1.9% | Feb 4, 2022 | A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. S... |
| CVE-2021-21959 | HIGH | 8.1 | 0.8% | Feb 4, 2022 | A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfigur... |
| CVE-2021-29397 | HIGH | 7.5 | 0.8% | Feb 4, 2022 | Cleartext Transmission of Sensitive Information in /northstar/Admin/login.jsp in Northstar Technologies Inc NorthStar Cl... |
| CVE-2021-29395 | HIGH | 7.5 | 1.8% | Feb 4, 2022 | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 al... |
| CVE-2021-46398 | HIGH | 8.8 | 6.7% | Feb 4, 2022 | A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use... |
| CVE-2021-44977 | HIGH | 7.5 | 1.6% | Feb 4, 2022 | In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. |
| CVE-2021-43145 | HIGH | 8.1 | 0.9% | Feb 4, 2022 | With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user acco... |
| CVE-2021-46320 | HIGH | 7.5 | 1.2% | Feb 4, 2022 | In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent exa... |
| CVE-2021-44903 | HIGH | 7.8 | 0.3% | Feb 4, 2022 | Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabi... |
| CVE-2021-44901 | HIGH | 7.8 | 0.5% | Feb 4, 2022 | Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulne... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now