2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22141 | MEDIUM | 6.1 | 0.5% | Nov 18, 2022 | An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously cr... |
| CVE-2021-36905 | MEDIUM | 5.4 | 0.4% | Nov 17, 2022 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.... |
| CVE-2021-31608 | MEDIUM | 4.3 | 0.4% | Nov 17, 2022 | Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control. |
| CVE-2021-33897 | MEDIUM | 5.5 | 0.2% | Nov 17, 2022 | A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to caus... |
| CVE-2021-38819 | HIGH | 8.8 | 0.9% | Nov 17, 2022 | A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the alb... |
| CVE-2021-4241 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedI... |
| CVE-2021-4240 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePassw... |
| CVE-2021-40272 | MEDIUM | 6.1 | 1.0% | Nov 14, 2022 | OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS). |
| CVE-2021-38828 | MEDIUM | 5.3 | 0.3% | Nov 14, 2022 | Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing. |
| CVE-2021-38827 | HIGH | 7.5 | 0.6% | Nov 14, 2022 | Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to account takeover. |
| CVE-2021-33164 | MEDIUM | 6.7 | 0.2% | Nov 11, 2022 | Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user... |
| CVE-2021-33159 | MEDIUM | 6.7 | 0.2% | Nov 11, 2022 | Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.... |
| CVE-2021-33064 | HIGH | 7.8 | 0.2% | Nov 11, 2022 | Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticat... |
| CVE-2021-26251 | MEDIUM | 6.5 | 0.6% | Nov 11, 2022 | Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potent... |
| CVE-2021-0185 | MEDIUM | 6.7 | 0.2% | Nov 10, 2022 | Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a ... |
| CVE-2021-40289 | MEDIUM | 6.1 | 0.5% | Nov 10, 2022 | mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2021-40226 | HIGH | 7.5 | 0.7% | Nov 10, 2022 | xpdfreader 4.03 is vulnerable to Buffer Overflow. |
| CVE-2021-46852 | HIGH | 7.5 | 0.4% | Nov 9, 2022 | The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affec... |
| CVE-2021-46851 | CRITICAL | 9.8 | 0.5% | Nov 9, 2022 | The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerabil... |
| CVE-2021-26393 | MEDIUM | 5.5 | 0.2% | Nov 9, 2022 | Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authentic... |
| CVE-2021-26392 | HIGH | 7.8 | 0.3% | Nov 9, 2022 | Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing ... |
| CVE-2021-26391 | HIGH | 7.8 | 0.2% | Nov 9, 2022 | Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker w... |
| CVE-2021-26360 | HIGH | 7.8 | 0.2% | Nov 9, 2022 | An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC... |
| CVE-2021-34579 | HIGH | 7.5 | 0.6% | Nov 9, 2022 | In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of th... |
| CVE-2021-34577 | MEDIUM | 6.5 | 0.3% | Nov 9, 2022 | In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded sh... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now