2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37038 | HIGH | 7.5 | 0.7% | Dec 7, 2021 | There is an Improper access control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may... |
| CVE-2021-42133 | HIGH | 8.1 | 2.8% | Dec 7, 2021 | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to th... |
| CVE-2021-42132 | HIGH | 8.8 | 70.1% | Dec 7, 2021 | A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail... |
| CVE-2021-42131 | HIGH | 8.8 | 66.5% | Dec 7, 2021 | A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Serv... |
| CVE-2021-42130 | HIGH | 8.8 | 62.2% | Dec 7, 2021 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access... |
| CVE-2021-42129 | HIGH | 8.8 | 77.3% | Dec 7, 2021 | A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail... |
| CVE-2021-42126 | HIGH | 8.8 | 3.9% | Dec 7, 2021 | An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access t... |
| CVE-2021-42125 | HIGH | 8.8 | 81.6% | Dec 7, 2021 | An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the ... |
| CVE-2021-42124 | HIGH | 8.8 | 2.6% | Dec 7, 2021 | An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the I... |
| CVE-2021-22956 | HIGH | 7.5 | 0.9% | Dec 7, 2021 | An uncontrolled resource consumption vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 that cou... |
| CVE-2021-22955 | HIGH | 7.5 | 0.9% | Dec 7, 2021 | A unauthenticated denial of service vulnerability exists in Citrix ADC <13.0-83.27, <12.1-63.22 and 11.1-65.23 when conf... |
| CVE-2021-28703 | HIGH | 7 | 0.3% | Dec 7, 2021 | grant table v2 status pages may remain accessible after de-allocation (take two) Guest get permitted access to certain X... |
| CVE-2021-44513 | HIGH | 7 | 0.2% | Dec 7, 2021 | Insecure creation of temporary directories in tmate-ssh-server 2.3.0 allows a local attacker to compromise the integrity... |
| CVE-2021-44512 | HIGH | 7 | 0.3% | Dec 7, 2021 | World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to comp... |
| CVE-2021-44686 | HIGH | 7.5 | 5.0% | Dec 7, 2021 | calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) i... |
| CVE-2021-31631 | HIGH | 8.8 | 0.5% | Dec 6, 2021 | b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulne... |
| CVE-2021-4075 | HIGH | 7.2 | 0.9% | Dec 6, 2021 | snipe-it is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2021-40313 | HIGH | 8.8 | 1.1% | Dec 6, 2021 | Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager... |
| CVE-2021-43800 | HIGH | 7.5 | 1.7% | Dec 6, 2021 | Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is poss... |
| CVE-2021-22170 | HIGH | 7.5 | 0.5% | Dec 6, 2021 | Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encr... |
| CVE-2021-36198 | HIGH | 7.5 | 1.1% | Dec 6, 2021 | Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data. |
| CVE-2021-35242 | HIGH | 8.8 | 0.7% | Dec 6, 2021 | Serv-U server responds with valid CSRFToken when the request contains only Session. |
| CVE-2021-24917 | HIGH | 7.5 | 71.5% | Dec 6, 2021 | The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random... |
| CVE-2021-24914 | HIGH | 8 | 0.5% | Dec 6, 2021 | The Tawk.To Live Chat WordPress plugin before 0.6.0 does not have capability and CSRF checks in the tawkto_setwidget and... |
| CVE-2021-43471 | HIGH | 7.5 | 1.4% | Dec 6, 2021 | In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can rem... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now