2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43436 | MEDIUM | 5.4 | 0.6% | Jan 12, 2022 | MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. ... |
| CVE-2021-44649 | MEDIUM | 5.4 | 0.6% | Jan 12, 2022 | Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type,... |
| CVE-2021-46283 | MEDIUM | 5.5 | 0.3% | Jan 11, 2022 | nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denia... |
| CVE-2021-41767 | MEDIUM | 6.5 | 1.9% | Jan 11, 2022 | Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some ... |
| CVE-2021-43974 | MEDIUM | 5.3 | 1.4% | Jan 11, 2022 | An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, ... |
| CVE-2021-43972 | MEDIUM | 6.5 | 1.5% | Jan 11, 2022 | An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authe... |
| CVE-2021-29701 | MEDIUM | 4.3 | 0.7% | Jan 11, 2022 | IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could a... |
| CVE-2021-44647 | MEDIUM | 5.5 | 0.4% | Jan 11, 2022 | Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a l... |
| CVE-2021-37196 | MEDIUM | 6.5 | 0.8% | Jan 11, 2022 | A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers... |
| CVE-2021-37195 | MEDIUM | 6.1 | 0.5% | Jan 11, 2022 | A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers... |
| CVE-2021-36411 | MEDIUM | 5.5 | 1.2% | Jan 10, 2022 | An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in fun... |
| CVE-2021-36410 | MEDIUM | 5.5 | 0.9% | Jan 10, 2022 | A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running p... |
| CVE-2021-36408 | MEDIUM | 5.5 | 0.8% | Jan 10, 2022 | An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265... |
| CVE-2021-35452 | MEDIUM | 6.5 | 1.3% | Jan 10, 2022 | An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc. |
| CVE-2021-43951 | MEDIUM | 4.3 | 0.8% | Jan 10, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi... |
| CVE-2021-43949 | MEDIUM | 4.3 | 0.8% | Jan 10, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi... |
| CVE-2021-25047 | MEDIUM | 6.1 | 0.8% | Jan 10, 2022 | The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulner... |
| CVE-2021-25043 | MEDIUM | 6.1 | 0.9% | Jan 10, 2022 | The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it ... |
| CVE-2021-46166 | MEDIUM | 6.5 | 2.8% | Jan 10, 2022 | Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the da... |
| CVE-2021-46163 | MEDIUM | 6.1 | 0.8% | Jan 10, 2022 | Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem. |
| CVE-2021-46150 | MEDIUM | 4.8 | 0.6% | Jan 10, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog... |
| CVE-2021-46148 | MEDIUM | 6.5 | 1.2% | Jan 10, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged us... |
| CVE-2021-46146 | MEDIUM | 5.4 | 0.6% | Jan 10, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInf... |
| CVE-2021-46055 | MEDIUM | 5.5 | 0.7% | Jan 10, 2022 | A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitReth... |
| CVE-2021-46054 | MEDIUM | 5.5 | 0.7% | Jan 10, 2022 | A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitReth... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now