2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45097 | MEDIUM | 5.5 | 0.2% | Dec 16, 2021 | KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's passwo... |
| CVE-2021-45096 | MEDIUM | 4.3 | 1.1% | Dec 16, 2021 | KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (... |
| CVE-2021-45095 | MEDIUM | 5.5 | 0.3% | Dec 16, 2021 | pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak. |
| CVE-2021-45088 | MEDIUM | 6.1 | 1.4% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. |
| CVE-2021-45087 | MEDIUM | 6.1 | 1.5% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used,... |
| CVE-2021-45086 | MEDIUM | 6.1 | 1.3% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used... |
| CVE-2021-45085 | MEDIUM | 6.1 | 1.5% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-a... |
| CVE-2021-45018 | MEDIUM | 6.1 | 0.6% | Dec 15, 2021 | Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admi... |
| CVE-2021-44116 | MEDIUM | 6.1 | 0.7% | Dec 15, 2021 | Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column t... |
| CVE-2021-35490 | MEDIUM | 5.4 | 0.5% | Dec 15, 2021 | Thruk before 2.44 allows XSS for a quick command. |
| CVE-2021-29847 | MEDIUM | 5.9 | 1.0% | Dec 15, 2021 | BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user t... |
| CVE-2021-27858 | MEDIUM | 5.3 | 2.7% | Dec 15, 2021 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t... |
| CVE-2021-39657 | MEDIUM | 4.4 | 0.2% | Dec 15, 2021 | In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. Thi... |
| CVE-2021-39656 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local ... |
| CVE-2021-39652 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In sec_ts_parsing_cmds of (TBD), there is a possible out of bounds write due to an incorrect bounds check. This could le... |
| CVE-2021-39650 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escal... |
| CVE-2021-39649 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In regmap_exit of regmap.c, there is a possible use-after-free due to improper locking. This could lead to local escalat... |
| CVE-2021-39648 | MEDIUM | 4.1 | 0.2% | Dec 15, 2021 | In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition.... |
| CVE-2021-39647 | MEDIUM | 4.4 | 0.1% | Dec 15, 2021 | In mon_smc_load_sp of gs101-sc/plat/samsung/exynos/soc/exynos9845/smc_booting.S, there is a possible reinitialization of... |
| CVE-2021-39643 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In ic_startRetrieveEntryValue of acropora/app/identity/ic.c, there is a possible bypass of defense-in-depth due to missi... |
| CVE-2021-39642 | MEDIUM | 6.4 | 0.1% | Dec 15, 2021 | In synchronous_process_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to a race condition. This... |
| CVE-2021-39639 | MEDIUM | 6.8 | 0.1% | Dec 15, 2021 | In TBD of fvp.c, there is a possible way to glitch CPU behavior due to a missing permission check. This could lead to lo... |
| CVE-2021-39638 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In periodic_io_work_func of lwis_periodic_io.c, there is a possible out of bounds write due to a use after free. This co... |
| CVE-2021-39637 | MEDIUM | 4.4 | 0.1% | Dec 15, 2021 | In CreateDeviceInfo of trusty_remote_provisioning_context.cpp, there is a possible out of bounds read due to a missing b... |
| CVE-2021-39636 | MEDIUM | 4.4 | 0.2% | Dec 15, 2021 | In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitial... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now