2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36338 | HIGH | 8 | 0.4% | Jan 21, 2022 | Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious us... |
| CVE-2021-23664 | HIGH | 7.5 | 1.4% | Jan 21, 2022 | The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing ... |
| CVE-2021-23631 | HIGH | 7.5 | 2.0% | Jan 21, 2022 | This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of packa... |
| CVE-2021-23460 | HIGH | 7.5 | 2.3% | Jan 21, 2022 | The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of... |
| CVE-2021-44593 | HIGH | 8.1 | 4.2% | Jan 21, 2022 | Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL inje... |
| CVE-2021-44464 | HIGH | 8.8 | 0.6% | Jan 21, 2022 | Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across al... |
| CVE-2021-41835 | HIGH | 7.5 | 0.3% | Jan 21, 2022 | Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be... |
| CVE-2021-33846 | HIGH | 7.2 | 0.3% | Jan 21, 2022 | Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticat... |
| CVE-2021-23236 | HIGH | 7.5 | 1.1% | Jan 21, 2022 | Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ versio... |
| CVE-2021-46334 | HIGH | 7.8 | 0.8% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat. |
| CVE-2021-46332 | HIGH | 7.8 | 1.0% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter. |
| CVE-2021-46328 | HIGH | 7.8 | 0.8% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main. |
| CVE-2021-46326 | HIGH | 7.8 | 0.9% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy. |
| CVE-2021-46325 | HIGH | 7.8 | 0.7% | Jan 20, 2022 | Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf. |
| CVE-2021-46324 | HIGH | 7.8 | 0.7% | Jan 20, 2022 | Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString. |
| CVE-2021-45417 | HIGH | 7.8 | 0.5% | Jan 20, 2022 | AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attribut... |
| CVE-2021-44737 | HIGH | 8.8 | 1.4% | Jan 20, 2022 | PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal ... |
| CVE-2021-43269 | HIGH | 8.8 | 1.3% | Jan 20, 2022 | In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a maliciou... |
| CVE-2021-23843 | HIGH | 7.8 | 0.2% | Jan 19, 2022 | The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices.... |
| CVE-2021-23842 | HIGH | 7.1 | 0.1% | Jan 19, 2022 | Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An a... |
| CVE-2021-38789 | HIGH | 7.5 | 1.3% | Jan 19, 2022 | Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the c... |
| CVE-2021-42810 | HIGH | 7.8 | 0.3% | Jan 19, 2022 | A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a priv... |
| CVE-2021-38788 | HIGH | 7.5 | 1.7% | Jan 19, 2022 | The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious app... |
| CVE-2021-46104 | HIGH | 7.5 | 4.2% | Jan 19, 2022 | An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi... |
| CVE-2021-45808 | HIGH | 8.8 | 1.6% | Jan 19, 2022 | jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the s... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now