2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43437 | HIGH | 8.8 | 1.2% | Dec 20, 2021 | In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the we... |
| CVE-2021-44224 | HIGH | 8.2 | 82.3% | Dec 20, 2021 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference... |
| CVE-2021-41561 | HIGH | 7.5 | 3.1% | Dec 20, 2021 | Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet f... |
| CVE-2021-44858 | HIGH | 7.5 | 1.3% | Dec 20, 2021 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us... |
| CVE-2021-42913 | HIGH | 7.5 | 1.8% | Dec 20, 2021 | The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and clea... |
| CVE-2021-44162 | HIGH | 7.5 | 1.7% | Dec 20, 2021 | Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has imprope... |
| CVE-2021-4136 | HIGH | 7.8 | 1.8% | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-45041 | HIGH | 8.8 | 2.2% | Dec 19, 2021 | SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project mo... |
| CVE-2021-43083 | HIGH | 8.8 | 1.9% | Dec 19, 2021 | Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow f... |
| CVE-2021-4131 | HIGH | 8.8 | 0.5% | Dec 18, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4130 | HIGH | 8.8 | 0.5% | Dec 18, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-41500 | HIGH | 7.5 | 1.2% | Dec 17, 2021 | Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholm... |
| CVE-2021-41499 | HIGH | 7.5 | 1.4% | Dec 17, 2021 | Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remo... |
| CVE-2021-41498 | HIGH | 7.5 | 1.1% | Dec 17, 2021 | Buffer overflow in ajaxsoundstudio.com Pyo < and 1.03 in the Server_jack_init function. which allows attackers to cond... |
| CVE-2021-41497 | HIGH | 7.5 | 1.0% | Dec 17, 2021 | Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows atta... |
| CVE-2021-23814 | HIGH | 8.8 | 1.8% | Dec 17, 2021 | This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficien... |
| CVE-2021-43838 | HIGH | 7.5 | 1.4% | Dec 17, 2021 | jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users... |
| CVE-2021-4011 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-4010 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-4009 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-4008 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-40853 | HIGH | 7.2 | 0.8% | Dec 17, 2021 | TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could ex... |
| CVE-2021-40851 | HIGH | 7.5 | 1.3% | Dec 17, 2021 | TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. Th... |
| CVE-2021-32499 | HIGH | 7.5 | 0.8% | Dec 17, 2021 | SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the... |
| CVE-2021-32498 | HIGH | 8.6 | 0.9% | Dec 17, 2021 | SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now