2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31872 | CRITICAL | 9.8 | 2.1% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems... |
| CVE-2021-31870 | CRITICAL | 9.8 | 2.1% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow... |
| CVE-2021-21388 | CRITICAL | 9.8 | 1.9% | Apr 29, 2021 | systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has... |
| CVE-2021-30234 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute a... |
| CVE-2021-30233 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arb... |
| CVE-2021-30232 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute ... |
| CVE-2021-30231 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbit... |
| CVE-2021-30230 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execu... |
| CVE-2021-30228 | CRITICAL | 9.8 | 3.3% | Apr 29, 2021 | The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execut... |
| CVE-2021-25812 | CRITICAL | 9.8 | 2.8% | Apr 29, 2021 | Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/... |
| CVE-2021-27651 | CRITICAL | 9.8 | 53.8% | Apr 29, 2021 | In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to byp... |
| CVE-2021-20090 | CRITICAL | 9.8 | 100.0% | Apr 29, 2021 | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 ... |
| CVE-2021-29145 | CRITICAL | 9.8 | 1.9% | Apr 29, 2021 | A remote server side request forgery (SSRF) remote code execution vulnerability was discovered in Aruba ClearPass Policy... |
| CVE-2021-31875 | CRITICAL | 9.8 | 2.2% | Apr 29, 2021 | In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buff... |
| CVE-2021-25216 | CRITICAL | 9.8 | 83.4% | Apr 29, 2021 | In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BI... |
| CVE-2021-22514 | CRITICAL | 9.8 | 2.0% | Apr 28, 2021 | An arbitrary code execution vulnerability exists in Micro Focus Application Performance Management, affecting versions 9... |
| CVE-2021-30168 | CRITICAL | 9.8 | 2.1% | Apr 28, 2021 | The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant adminis... |
| CVE-2021-30167 | CRITICAL | 9.8 | 2.4% | Apr 28, 2021 | The manage users profile services of the network camera device allows an authenticated. Remote attackers can modify URL ... |
| CVE-2021-31856 | CRITICAL | 9.8 | 75.4% | Apr 28, 2021 | A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL comman... |
| CVE-2021-20716 | CRITICAL | 9.8 | 3.2% | Apr 28, 2021 | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 ... |
| CVE-2021-29476 | CRITICAL | 9.8 | 2.1% | Apr 27, 2021 | Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p... |
| CVE-2021-29441 | CRITICAL | 9.8 | 74.8% | Apr 27, 2021 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver... |
| CVE-2021-30128 | CRITICAL | 9.8 | 81.1% | Apr 27, 2021 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version |
| CVE-2021-29200 | CRITICAL | 9.8 | 55.4% | Apr 27, 2021 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack |
| CVE-2021-30642 | CRITICAL | 9.8 | 2.7% | Apr 27, 2021 | An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now