2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22345 | CRITICAL | 9.8 | 0.8% | Jun 30, 2021 | There is an Input Verification Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cau... |
| CVE-2021-22348 | CRITICAL | 9.8 | 0.8% | Jun 30, 2021 | There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vu... |
| CVE-2021-22367 | CRITICAL | 9.8 | 0.8% | Jun 30, 2021 | There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may l... |
| CVE-2021-22354 | CRITICAL | 9.1 | 0.8% | Jun 30, 2021 | There is an Information Disclosure Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may... |
| CVE-2021-35973 | CRITICAL | 9.8 | 3.1% | Jun 30, 2021 | NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, a... |
| CVE-2021-35971 | CRITICAL | 9.8 | 1.2% | Jun 30, 2021 | Veeam Backup and Replication 10 before 10.0.1.4854 P20210609 and 11 before 11.0.0.837 P20210507 mishandles deserializati... |
| CVE-2021-22373 | CRITICAL | 9.1 | 0.7% | Jun 30, 2021 | There is a Defects Introduced in the Design Process Vulnerability in Huawei Smartphone. Successful exploitation of this ... |
| CVE-2021-22323 | CRITICAL | 9.8 | 0.9% | Jun 30, 2021 | There is an Integer Overflow Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may es... |
| CVE-2021-22380 | CRITICAL | 9.1 | 0.6% | Jun 30, 2021 | There is a Cleartext Transmission of Sensitive Information Vulnerability in Huawei Smartphone. Successful exploitation o... |
| CVE-2021-22375 | CRITICAL | 9.8 | 0.8% | Jun 30, 2021 | There is a Key Management Errors Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may a... |
| CVE-2021-27903 | CRITICAL | 9.8 | 2.8% | Jun 30, 2021 | An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerabilit... |
| CVE-2021-30648 | CRITICAL | 9.8 | 1.4% | Jun 30, 2021 | The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypa... |
| CVE-2021-35474 | CRITICAL | 9.8 | 2.7% | Jun 30, 2021 | Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic... |
| CVE-2021-35958 | CRITICAL | 9.1 | 1.9% | Jun 30, 2021 | TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_fil... |
| CVE-2021-32992 | CRITICAL | 9.8 | 1.8% | Jun 29, 2021 | FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory ... |
| CVE-2021-32990 | CRITICAL | 9.8 | 1.8% | Jun 29, 2021 | FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attack... |
| CVE-2021-32988 | CRITICAL | 9.8 | 1.8% | Jun 29, 2021 | FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attac... |
| CVE-2021-31531 | CRITICAL | 9.8 | 2.4% | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). |
| CVE-2021-31838 | CRITICAL | 9.1 | 2.0% | Jun 29, 2021 | A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to t... |
| CVE-2021-34187 | CRITICAL | 9.8 | 15.6% | Jun 28, 2021 | main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 p... |
| CVE-2021-35456 | CRITICAL | 9.8 | 2.1% | Jun 28, 2021 | Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload |
| CVE-2021-31337 | CRITICAL | 9.8 | 1.7% | Jun 28, 2021 | The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authenticati... |
| CVE-2021-35514 | CRITICAL | 9.8 | 1.4% | Jun 28, 2021 | Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel. |
| CVE-2021-23399 | CRITICAL | 9.8 | 1.3% | Jun 28, 2021 | This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, ... |
| CVE-2021-35502 | CRITICAL | 9.8 | 1.1% | Jun 25, 2021 | app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data rel... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now