2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46336 | MEDIUM | 5.5 | 0.6% | Jan 20, 2022 | There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_clas... |
| CVE-2021-46335 | MEDIUM | 5.5 | 0.8% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInst... |
| CVE-2021-46333 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove. |
| CVE-2021-46331 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype. |
| CVE-2021-46330 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_protot... |
| CVE-2021-46329 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini. |
| CVE-2021-46327 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort. |
| CVE-2021-46323 | MEDIUM | 5.5 | 0.6% | Jan 20, 2022 | Espruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass. |
| CVE-2021-46322 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack... |
| CVE-2021-29785 | MEDIUM | 5.9 | 1.3% | Jan 20, 2022 | IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to pro... |
| CVE-2021-44091 | MEDIUM | 5.4 | 0.6% | Jan 20, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in reg... |
| CVE-2021-44829 | MEDIUM | 6.1 | 1.6% | Jan 20, 2022 | Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter. |
| CVE-2021-32039 | MEDIUM | 5.5 | 0.3% | Jan 20, 2022 | Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS ... |
| CVE-2021-34600 | MEDIUM | 5.5 | 0.4% | Jan 20, 2022 | Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used... |
| CVE-2021-45230 | MEDIUM | 6.5 | 1.7% | Jan 20, 2022 | In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on D... |
| CVE-2021-3866 | MEDIUM | 5.4 | 0.9% | Jan 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6... |
| CVE-2021-46028 | MEDIUM | 4.3 | 0.4% | Jan 20, 2022 | In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF loa... |
| CVE-2021-46026 | MEDIUM | 5.4 | 0.4% | Jan 20, 2022 | mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag... |
| CVE-2021-4143 | MEDIUM | 6.1 | 0.9% | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. |
| CVE-2021-46027 | MEDIUM | 6.5 | 0.4% | Jan 19, 2022 | mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSR... |
| CVE-2021-46025 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in... |
| CVE-2021-44777 | MEDIUM | 4.3 | 0.4% | Jan 19, 2022 | Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email ... |
| CVE-2021-3816 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix fi... |
| CVE-2021-26247 | MEDIUM | 6.1 | 7.1% | Jan 19, 2022 | As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" t... |
| CVE-2021-23225 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now