2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46203 | MEDIUM | 6.5 | 1.1% | Jan 19, 2022 | Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. |
| CVE-2021-44299 | MEDIUM | 5.4 | 0.4% | Jan 19, 2022 | A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows au... |
| CVE-2021-46030 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into t... |
| CVE-2021-44837 | MEDIUM | 4.3 | 0.8% | Jan 19, 2022 | An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an ad... |
| CVE-2021-35687 | MEDIUM | 5.3 | 1.1% | Jan 19, 2022 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2021-35686 | MEDIUM | 4.3 | 0.7% | Jan 19, 2022 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2021-31821 | MEDIUM | 5.5 | 0.2% | Jan 19, 2022 | When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which w... |
| CVE-2021-44839 | MEDIUM | 6.5 | 0.6% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the accoun... |
| CVE-2021-44838 | MEDIUM | 4.3 | 0.9% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating ... |
| CVE-2021-44836 | MEDIUM | 4.3 | 0.6% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it i... |
| CVE-2021-46005 | MEDIUM | 5.4 | 2.9% | Jan 18, 2022 | Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter... |
| CVE-2021-34406 | MEDIUM | 4.7 | 0.2% | Jan 18, 2022 | NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointe... |
| CVE-2021-34405 | MEDIUM | 5.5 | 0.2% | Jan 18, 2022 | NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value c... |
| CVE-2021-34402 | MEDIUM | 6.7 | 0.3% | Jan 18, 2022 | NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to ... |
| CVE-2021-4074 | MEDIUM | 5.4 | 0.6% | Jan 18, 2022 | The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter fou... |
| CVE-2021-41809 | MEDIUM | 4.3 | 0.6% | Jan 18, 2022 | SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making qu... |
| CVE-2021-39946 | MEDIUM | 5.4 | 1.0% | Jan 18, 2022 | Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowe... |
| CVE-2021-39942 | MEDIUM | 6.5 | 1.4% | Jan 18, 2022 | A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions ... |
| CVE-2021-39927 | MEDIUM | 4.3 | 0.6% | Jan 18, 2022 | Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and ... |
| CVE-2021-39892 | MEDIUM | 4.3 | 1.2% | Jan 18, 2022 | In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don... |
| CVE-2021-37867 | MEDIUM | 4.3 | 0.7% | Jan 18, 2022 | Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, w... |
| CVE-2021-37865 | MEDIUM | 5.7 | 0.9% | Jan 18, 2022 | Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while draft... |
| CVE-2021-37864 | MEDIUM | 6.5 | 0.6% | Jan 18, 2022 | Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth... |
| CVE-2021-29872 | MEDIUM | 5.4 | 0.8% | Jan 18, 2022 | IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injec... |
| CVE-2021-4146 | MEDIUM | 4.3 | 0.8% | Jan 18, 2022 | Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now