2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45516 | MEDIUM | 4.5 | 0.4% | Dec 26, 2021 | Certain NETGEAR devices are affected by denial of service. This affects R6400 before 1.0.1.70, R7000 before 1.0.11.126, ... |
| CVE-2021-45515 | MEDIUM | 6.5 | 0.4% | Dec 26, 2021 | Certain NETGEAR devices are affected by denial of service. This affects EX7500 before 1.0.0.72, RBS40V before 2.6.1.4, R... |
| CVE-2021-45494 | MEDIUM | 4.5 | 0.4% | Dec 26, 2021 | Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects RBK352 before 4.4.0.... |
| CVE-2021-4162 | MEDIUM | 4.3 | 0.4% | Dec 25, 2021 | archivy is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-45483 | MEDIUM | 6.5 | 1.4% | Dec 25, 2021 | In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-3... |
| CVE-2021-45482 | MEDIUM | 6.5 | 1.4% | Dec 25, 2021 | In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability t... |
| CVE-2021-45481 | MEDIUM | 6.5 | 1.4% | Dec 25, 2021 | In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create... |
| CVE-2021-45480 | MEDIUM | 5.5 | 0.4% | Dec 24, 2021 | An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function i... |
| CVE-2021-3977 | MEDIUM | 5.4 | 0.6% | Dec 24, 2021 | invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4072 | MEDIUM | 5.4 | 0.7% | Dec 24, 2021 | elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-20876 | MEDIUM | 6.8 | 1.0% | Dec 24, 2021 | Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlie... |
| CVE-2021-20875 | MEDIUM | 6.1 | 0.8% | Dec 24, 2021 | Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier... |
| CVE-2021-45474 | MEDIUM | 6.1 | 1.0% | Dec 24, 2021 | In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl pa... |
| CVE-2021-45473 | MEDIUM | 6.1 | 1.2% | Dec 24, 2021 | In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (... |
| CVE-2021-45472 | MEDIUM | 6.1 | 1.0% | Dec 24, 2021 | In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that ... |
| CVE-2021-45471 | MEDIUM | 5.3 | 1.2% | Dec 24, 2021 | In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. |
| CVE-2021-3622 | MEDIUM | 4.3 | 4.8% | Dec 23, 2021 | A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive)... |
| CVE-2021-4024 | MEDIUM | 6.5 | 1.1% | Dec 23, 2021 | A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a... |
| CVE-2021-44543 | MEDIUM | 6.1 | 0.8% | Dec 23, 2021 | An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Pr... |
| CVE-2021-30767 | MEDIUM | 5.5 | 0.3% | Dec 23, 2021 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey ... |
| CVE-2021-27006 | MEDIUM | 4.4 | 0.3% | Dec 23, 2021 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may... |
| CVE-2021-43849 | MEDIUM | 5.5 | 0.3% | Dec 23, 2021 | cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both... |
| CVE-2021-4068 | MEDIUM | 6.5 | 1.3% | Dec 23, 2021 | Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cr... |
| CVE-2021-4059 | MEDIUM | 6.5 | 1.3% | Dec 23, 2021 | Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-or... |
| CVE-2021-4054 | MEDIUM | 6.5 | 1.2% | Dec 23, 2021 | Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now