2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41265 | HIGH | 8.8 | 1.3% | Dec 9, 2021 | Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentica... |
| CVE-2021-40282 | HIGH | 8.8 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary... |
| CVE-2021-40281 | HIGH | 8.8 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary use... |
| CVE-2021-39002 | HIGH | 7.5 | 0.9% | Dec 9, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expec... |
| CVE-2021-38951 | HIGH | 7.5 | 1.5% | Dec 9, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia... |
| CVE-2021-29678 | HIGH | 8.7 | 1.1% | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user wit... |
| CVE-2021-22568 | HIGH | 8.8 | 0.9% | Dec 9, 2021 | When using the dart pub publish command to publish a package to a third-party package server, the request would be authe... |
| CVE-2021-20373 | HIGH | 7.5 | 1.5% | Dec 9, 2021 | IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as un... |
| CVE-2021-41246 | HIGH | 8.8 | 0.9% | Dec 9, 2021 | Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions... |
| CVE-2021-40280 | HIGH | 7.2 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php. |
| CVE-2021-40279 | HIGH | 7.2 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php. |
| CVE-2021-21955 | HIGH | 7.5 | 1.0% | Dec 9, 2021 | An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary... |
| CVE-2021-20145 | HIGH | 7.5 | 1.2% | Dec 9, 2021 | Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon ... |
| CVE-2021-20144 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server ser... |
| CVE-2021-20143 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server ser... |
| CVE-2021-20142 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server ser... |
| CVE-2021-20141 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server ser... |
| CVE-2021-20140 | HIGH | 8.8 | 4.0% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server ser... |
| CVE-2021-20139 | HIGH | 8.8 | 4.0% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server serv... |
| CVE-2021-20138 | HIGH | 8.8 | 3.7% | Dec 9, 2021 | An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web inter... |
| CVE-2021-41449 | HIGH | 7.1 | 1.7% | Dec 9, 2021 | A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote ... |
| CVE-2021-43071 | HIGH | 8.8 | 1.2% | Dec 9, 2021 | A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and b... |
| CVE-2021-43068 | HIGH | 8.1 | 0.6% | Dec 9, 2021 | A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authen... |
| CVE-2021-43065 | HIGH | 7.8 | 0.4% | Dec 9, 2021 | A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, ver... |
| CVE-2021-36194 | HIGH | 8.8 | 1.4% | Dec 9, 2021 | Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now