2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38787 | HIGH | 7.5 | 1.9% | Jan 19, 2022 | There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the io... |
| CVE-2021-38786 | HIGH | 7.5 | 1.8% | Jan 19, 2022 | There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could ca... |
| CVE-2021-31854 | HIGH | 7.8 | 1.0% | Jan 19, 2022 | A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary... |
| CVE-2021-34404 | HIGH | 7.6 | 0.2% | Jan 18, 2022 | Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA whe... |
| CVE-2021-34403 | HIGH | 7.8 | 0.3% | Jan 18, 2022 | NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit... |
| CVE-2021-34401 | HIGH | 7.8 | 0.3% | Jan 18, 2022 | NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where imprope... |
| CVE-2021-4083 | HIGH | 7 | 0.3% | Jan 18, 2022 | A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in... |
| CVE-2021-43353 | HIGH | 8.8 | 0.6% | Jan 18, 2022 | The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the... |
| CVE-2021-37866 | HIGH | 7.5 | 0.7% | Jan 18, 2022 | Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of ... |
| CVE-2021-29632 | HIGH | 7.5 | 0.9% | Jan 18, 2022 | In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE... |
| CVE-2021-41550 | HIGH | 7.2 | 1.0% | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. |
| CVE-2021-38696 | HIGH | 7.5 | 1.7% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature fi... |
| CVE-2021-38785 | HIGH | 7.5 | 1.8% | Jan 18, 2022 | There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could u... |
| CVE-2021-38784 | HIGH | 7.5 | 1.8% | Jan 18, 2022 | There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that coul... |
| CVE-2021-38694 | HIGH | 7.5 | 1.5% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection. |
| CVE-2021-38783 | HIGH | 7.5 | 1.8% | Jan 18, 2022 | There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl ... |
| CVE-2021-33965 | HIGH | 8.8 | 2.9% | Jan 18, 2022 | China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by ... |
| CVE-2021-45394 | HIGH | 8.8 | 1.6% | Jan 18, 2022 | An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the ... |
| CVE-2021-33964 | HIGH | 8.8 | 2.9% | Jan 18, 2022 | China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives ... |
| CVE-2021-38965 | HIGH | 8.8 | 1.8% | Jan 17, 2022 | IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary com... |
| CVE-2021-4164 | HIGH | 8.8 | 0.5% | Jan 17, 2022 | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-25036 | HIGH | 8.8 | 3.0% | Jan 17, 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur... |
| CVE-2021-44537 | HIGH | 7.8 | 2.7% | Jan 15, 2022 | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t... |
| CVE-2021-33828 | HIGH | 8.8 | 1.2% | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th... |
| CVE-2021-33827 | HIGH | 7.2 | 2.1% | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now