2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28300 | CRITICAL | 9.8 | 2.1% | Apr 14, 2021 | NULL Pointer Dereference in the "isomedia/track.c" module's "MergeTrack()" function of GPAC v0.5.2 allows attackers to e... |
| CVE-2021-27114 | CRITICAL | 9.8 | 24.6% | Apr 14, 2021 | An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment ... |
| CVE-2021-27113 | CRITICAL | 9.8 | 3.5% | Apr 14, 2021 | An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string const... |
| CVE-2021-28797 | CRITICAL | 9.8 | 5.9% | Apr 14, 2021 | A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. I... |
| CVE-2021-31162 | CRITICAL | 9.8 | 2.9% | Apr 14, 2021 | In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the ele... |
| CVE-2021-24028 | CRITICAL | 9.8 | 1.7% | Apr 14, 2021 | An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code e... |
| CVE-2021-3460 | CRITICAL | 9.8 | 0.6% | Apr 13, 2021 | The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communicat... |
| CVE-2021-28483 | CRITICAL | 9 | 1.2% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28481 | CRITICAL | 9.8 | 36.5% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28480 | CRITICAL | 9.8 | 71.4% | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27602 | CRITICAL | 9.9 | 2.0% | Apr 13, 2021 | SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create ... |
| CVE-2021-23281 | CRITICAL | 10 | 2.2% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability... |
| CVE-2021-23280 | CRITICAL | 9.9 | 0.9% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. ... |
| CVE-2021-23279 | CRITICAL | 10 | 27.1% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability... |
| CVE-2021-23278 | CRITICAL | 9.6 | 1.0% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to authenticated arbitrary file delete vulnerability i... |
| CVE-2021-23277 | CRITICAL | 10 | 1.0% | Apr 13, 2021 | Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The s... |
| CVE-2021-0430 | CRITICAL | 9.8 | 2.8% | Apr 13, 2021 | In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could... |
| CVE-2021-29999 | CRITICAL | 9.8 | 1.8% | Apr 13, 2021 | An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server. |
| CVE-2021-29998 | CRITICAL | 9.8 | 2.4% | Apr 13, 2021 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. |
| CVE-2021-21730 | CRITICAL | 9.8 | 1.0% | Apr 13, 2021 | A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to acc... |
| CVE-2021-30176 | CRITICAL | 9.8 | 29.0% | Apr 13, 2021 | The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/dev... |
| CVE-2021-30175 | CRITICAL | 9.8 | 8.5% | Apr 13, 2021 | ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. |
| CVE-2021-22505 | CRITICAL | 9.8 | 1.5% | Apr 13, 2021 | Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12.... |
| CVE-2021-29943 | CRITICAL | 9.1 | 5.3% | Apr 13, 2021 | When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/p... |
| CVE-2021-27905 | CRITICAL | 9.8 | 93.1% | Apr 13, 2021 | The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now