2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36739 | MEDIUM | 6.1 | 2.3% | Jan 6, 2022 | The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to ... |
| CVE-2021-36738 | MEDIUM | 6.1 | 2.3% | Jan 6, 2022 | The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scrip... |
| CVE-2021-36737 | MEDIUM | 6.1 | 2.3% | Jan 6, 2022 | The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should m... |
| CVE-2021-46145 | MEDIUM | 5.3 | 3.6% | Jan 6, 2022 | The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expirin... |
| CVE-2021-46144 | MEDIUM | 6.1 | 1.0% | Jan 6, 2022 | Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets... |
| CVE-2021-46142 | MEDIUM | 5.5 | 1.1% | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
| CVE-2021-46141 | MEDIUM | 5.5 | 1.1% | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeO... |
| CVE-2021-46038 | MEDIUM | 5.5 | 0.6% | Jan 5, 2022 | A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context... |
| CVE-2021-45833 | MEDIUM | 5.5 | 0.7% | Jan 5, 2022 | A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in... |
| CVE-2021-45832 | MEDIUM | 5.5 | 0.7% | Jan 5, 2022 | A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Se... |
| CVE-2021-45831 | MEDIUM | 5.5 | 0.6% | Jan 5, 2022 | A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Serv... |
| CVE-2021-45830 | MEDIUM | 5.5 | 0.7% | Jan 5, 2022 | A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which ... |
| CVE-2021-28713 | MEDIUM | 6.5 | 0.3% | Jan 5, 2022 | Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; ... |
| CVE-2021-28712 | MEDIUM | 6.5 | 0.3% | Jan 5, 2022 | Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; ... |
| CVE-2021-28711 | MEDIUM | 6.5 | 0.3% | Jan 5, 2022 | Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; ... |
| CVE-2021-41043 | MEDIUM | 5.5 | 0.9% | Jan 5, 2022 | Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact. |
| CVE-2021-31589 | MEDIUM | 6.1 | 28.3% | Jan 5, 2022 | A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Sof... |
| CVE-2021-43946 | MEDIUM | 6.5 | 1.1% | Jan 5, 2022 | Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator gro... |
| CVE-2021-45452 | MEDIUM | 5.3 | 2.4% | Jan 5, 2022 | Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted ... |
| CVE-2021-43850 | MEDIUM | 6.8 | 0.8% | Jan 4, 2022 | Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of... |
| CVE-2021-43677 | MEDIUM | 6.1 | 0.6% | Jan 4, 2022 | Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability. |
| CVE-2021-41236 | MEDIUM | 4.8 | 0.7% | Jan 4, 2022 | OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS... |
| CVE-2021-41789 | MEDIUM | 6.5 | 0.6% | Jan 4, 2022 | In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of ... |
| CVE-2021-40111 | MEDIUM | 6.5 | 2.1% | Jan 4, 2022 | In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP comma... |
| CVE-2021-38542 | MEDIUM | 5.9 | 2.3% | Jan 4, 2022 | Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now