2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43851 | HIGH | 8.8 | 1.2% | Dec 22, 2021 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability ex... |
| CVE-2021-44860 | HIGH | 7.8 | 0.8% | Dec 21, 2021 | An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.1... |
| CVE-2021-44859 | HIGH | 7.8 | 0.8% | Dec 21, 2021 | An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.1... |
| CVE-2021-44423 | HIGH | 7.8 | 0.8% | Dec 21, 2021 | An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer be... |
| CVE-2021-44422 | HIGH | 7.8 | 0.9% | Dec 21, 2021 | An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before... |
| CVE-2021-45290 | HIGH | 7.5 | 1.5% | Dec 21, 2021 | A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable. |
| CVE-2021-44207 | HIGH | 8.1 | 17.6% | Dec 21, 2021 | Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials. |
| CVE-2021-27449 | HIGH | 8.8 | 3.1% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute comman... |
| CVE-2021-27445 | HIGH | 7.8 | 0.2% | Dec 21, 2021 | Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges ... |
| CVE-2021-44877 | HIGH | 7.5 | 1.0% | Dec 21, 2021 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP s... |
| CVE-2021-44874 | HIGH | 8.8 | 1.0% | Dec 21, 2021 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam ap... |
| CVE-2021-43839 | HIGH | 7.5 | 1.3% | Dec 21, 2021 | Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to... |
| CVE-2021-36350 | HIGH | 7.5 | 1.1% | Dec 21, 2021 | Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authen... |
| CVE-2021-36337 | HIGH | 7.4 | 0.4% | Dec 21, 2021 | Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 whi... |
| CVE-2021-36316 | HIGH | 7.2 | 0.7% | Dec 21, 2021 | Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability ... |
| CVE-2021-24981 | HIGH | 7.5 | 0.8% | Dec 21, 2021 | The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leadi... |
| CVE-2021-24846 | HIGH | 8.8 | 1.3% | Dec 21, 2021 | The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_a... |
| CVE-2021-24750 | HIGH | 8.8 | 38.6% | Dec 21, 2021 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refU... |
| CVE-2021-24739 | HIGH | 8.1 | 1.0% | Dec 21, 2021 | The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb... |
| CVE-2021-45451 | HIGH | 7.5 | 0.8% | Dec 21, 2021 | In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer... |
| CVE-2021-45450 | HIGH | 7.5 | 1.1% | Dec 21, 2021 | In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or ora... |
| CVE-2021-43844 | HIGH | 8.8 | 3.3% | Dec 20, 2021 | MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirec... |
| CVE-2021-43843 | HIGH | 7.5 | 1.9% | Dec 20, 2021 | jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch ... |
| CVE-2021-3860 | HIGH | 8.8 | 1.0% | Dec 20, 2021 | JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged... |
| CVE-2021-44181 | HIGH | 7.8 | 3.1% | Dec 20, 2021 | Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now