2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31566 | HIGH | 7.8 | 0.4% | Aug 23, 2022 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control ... |
| CVE-2021-23177 | HIGH | 7.8 | 0.4% | Aug 23, 2022 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the t... |
| CVE-2021-23161 | — | — | — | Aug 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-23156 | — | — | — | Aug 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20316 | MEDIUM | 6.8 | 0.8% | Aug 23, 2022 | A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permi... |
| CVE-2021-20304 | HIGH | 7.5 | 1.5% | Aug 23, 2022 | A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be pr... |
| CVE-2021-20298 | HIGH | 7.5 | 1.2% | Aug 23, 2022 | A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed ... |
| CVE-2021-42627 | CRITICAL | 9.8 | 67.9% | Aug 23, 2022 | The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without auth... |
| CVE-2021-42232 | CRITICAL | 9.8 | 3.2% | Aug 23, 2022 | TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnera... |
| CVE-2021-28861 | HIGH | 7.4 | 2.0% | Aug 23, 2022 | Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multipl... |
| CVE-2021-29891 | MEDIUM | 4.9 | 0.4% | Aug 22, 2022 | IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause... |
| CVE-2021-3484 | — | — | — | Aug 22, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3408 | — | — | — | Aug 22, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3659 | MEDIUM | 5.5 | 0.3% | Aug 22, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way t... |
| CVE-2021-3639 | MEDIUM | 6.1 | 0.8% | Aug 22, 2022 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an atta... |
| CVE-2021-3590 | HIGH | 8.8 | 0.6% | Aug 22, 2022 | A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password t... |
| CVE-2021-3586 | CRITICAL | 9.8 | 0.9% | Aug 22, 2022 | A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify whic... |
| CVE-2021-3521 | MEDIUM | 4.7 | 0.3% | Aug 22, 2022 | There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signa... |
| CVE-2021-3513 | HIGH | 7.5 | 0.7% | Aug 22, 2022 | A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. ... |
| CVE-2021-3481 | HIGH | 7.1 | 0.5% | Aug 22, 2022 | A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/... |
| CVE-2021-3442 | MEDIUM | 5.4 | 0.4% | Aug 22, 2022 | A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated ... |
| CVE-2021-37289 | HIGH | 7.2 | 1.4% | Aug 22, 2022 | Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system c... |
| CVE-2021-36857 | MEDIUM | 5.4 | 0.5% | Aug 22, 2022 | Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.... |
| CVE-2021-36852 | HIGH | 8 | 0.3% | Aug 22, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress. |
| CVE-2021-36847 | MEDIUM | 4.8 | 0.5% | Aug 22, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now