2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32497 | HIGH | 8.6 | 0.7% | Dec 17, 2021 | SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ... |
| CVE-2021-22054 | HIGH | 7.5 | 97.7% | Dec 17, 2021 | VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and ... |
| CVE-2021-20608 | HIGH | 7.5 | 2.7% | Dec 17, 2021 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and p... |
| CVE-2021-0673 | HIGH | 7.8 | 0.7% | Dec 17, 2021 | In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local ... |
| CVE-2021-44035 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and... |
| CVE-2021-41451 | HIGH | 7.5 | 3.2% | Dec 17, 2021 | A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unau... |
| CVE-2021-36780 | HIGH | 8.1 | 0.5% | Dec 17, 2021 | A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to... |
| CVE-2021-44315 | HIGH | 7.5 | 1.7% | Dec 16, 2021 | In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to ... |
| CVE-2021-41262 | HIGH | 8.8 | 1.1% | Dec 16, 2021 | Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions... |
| CVE-2021-41028 | HIGH | 7.5 | 0.2% | Dec 16, 2021 | A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 ... |
| CVE-2021-38244 | HIGH | 7.5 | 1.2% | Dec 16, 2021 | A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to ... |
| CVE-2021-37262 | HIGH | 7.5 | 1.0% | Dec 16, 2021 | JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. |
| CVE-2021-41260 | HIGH | 8.8 | 0.4% | Dec 16, 2021 | Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions... |
| CVE-2021-42912 | HIGH | 8.8 | 14.1% | Dec 16, 2021 | FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows th... |
| CVE-2021-3960 | HIGH | 7.8 | 0.3% | Dec 16, 2021 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer compone... |
| CVE-2021-3959 | HIGH | 7.5 | 1.7% | Dec 16, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To... |
| CVE-2021-45102 | HIGH | 8.8 | 0.9% | Dec 16, 2021 | An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon... |
| CVE-2021-45101 | HIGH | 8.1 | 0.9% | Dec 16, 2021 | An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-li... |
| CVE-2021-45100 | HIGH | 7.5 | 0.9% | Dec 16, 2021 | The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even tho... |
| CVE-2021-45099 | HIGH | 8.8 | 1.3% | Dec 16, 2021 | The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an atta... |
| CVE-2021-45098 | HIGH | 7.5 | 1.8% | Dec 16, 2021 | An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an R... |
| CVE-2021-44023 | HIGH | 7.1 | 0.4% | Dec 16, 2021 | A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products c... |
| CVE-2021-43833 | HIGH | 8.8 | 0.8% | Dec 16, 2021 | eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh... |
| CVE-2021-45017 | HIGH | 8.8 | 0.4% | Dec 15, 2021 | Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on... |
| CVE-2021-45078 | HIGH | 7.8 | 1.3% | Dec 15, 2021 | stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-base... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now