2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43255 | MEDIUM | 5.5 | 2.0% | Dec 15, 2021 | Microsoft Office Trust Center Spoofing Vulnerability |
| CVE-2021-43246 | MEDIUM | 5.6 | 0.8% | Dec 15, 2021 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2021-43244 | MEDIUM | 5.5 | 0.8% | Dec 15, 2021 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2021-43243 | MEDIUM | 5.5 | 0.8% | Dec 15, 2021 | VP9 Video Extensions Information Disclosure Vulnerability |
| CVE-2021-43242 | MEDIUM | 5.7 | 1.2% | Dec 15, 2021 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2021-43235 | MEDIUM | 5.5 | 0.8% | Dec 15, 2021 | Storage Spaces Controller Information Disclosure Vulnerability |
| CVE-2021-43227 | MEDIUM | 5.5 | 0.8% | Dec 15, 2021 | Storage Spaces Controller Information Disclosure Vulnerability |
| CVE-2021-43224 | MEDIUM | 5.5 | 3.9% | Dec 15, 2021 | Windows Common Log File System Driver Information Disclosure Vulnerability |
| CVE-2021-43216 | MEDIUM | 6.5 | 3.2% | Dec 15, 2021 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability |
| CVE-2021-42320 | MEDIUM | 5.7 | 1.5% | Dec 15, 2021 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2021-42295 | MEDIUM | 5.5 | 2.9% | Dec 15, 2021 | Visual Basic for Applications Information Disclosure Vulnerability |
| CVE-2021-42293 | MEDIUM | 6.5 | 2.8% | Dec 15, 2021 | Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability |
| CVE-2021-4116 | MEDIUM | 5.4 | 0.5% | Dec 15, 2021 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-20330 | MEDIUM | 6.5 | 1.0% | Dec 15, 2021 | An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed... |
| CVE-2021-4111 | MEDIUM | 4.3 | 0.6% | Dec 15, 2021 | yetiforcecrm is vulnerable to Business Logic Errors |
| CVE-2021-42220 | MEDIUM | 5.4 | 0.9% | Dec 15, 2021 | A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation r... |
| CVE-2021-41557 | MEDIUM | 5.4 | 0.8% | Dec 15, 2021 | Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a use... |
| CVE-2021-40171 | MEDIUM | 5.3 | 0.9% | Dec 15, 2021 | The absence of notifications regarding an ongoing RF jamming attack in the SecuritasHome home alarm system, version HPGW... |
| CVE-2021-40170 | MEDIUM | 6.8 | 0.9% | Dec 15, 2021 | An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30... |
| CVE-2021-38701 | MEDIUM | 4.8 | 0.5% | Dec 15, 2021 | Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; ... |
| CVE-2021-36450 | MEDIUM | 6.1 | 69.4% | Dec 15, 2021 | Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter. |
| CVE-2021-26787 | MEDIUM | 6.1 | 1.0% | Dec 15, 2021 | A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion)... |
| CVE-2021-41871 | MEDIUM | 5.4 | 0.5% | Dec 15, 2021 | An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes ... |
| CVE-2021-43827 | MEDIUM | 4.3 | 0.8% | Dec 14, 2021 | discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote w... |
| CVE-2021-44942 | MEDIUM | 4.3 | 0.3% | Dec 14, 2021 | glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_be... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now