2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4092 | MEDIUM | 4.3 | 0.4% | Dec 11, 2021 | yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-43815 | MEDIUM | 4.3 | 1.8% | Dec 10, 2021 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a di... |
| CVE-2021-4089 | MEDIUM | 4.3 | 0.7% | Dec 10, 2021 | snipe-it is vulnerable to Improper Access Control |
| CVE-2021-31747 | MEDIUM | 4.8 | 0.3% | Dec 10, 2021 | Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-mid... |
| CVE-2021-43813 | MEDIUM | 4.3 | 58.0% | Dec 10, 2021 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains... |
| CVE-2021-38937 | MEDIUM | 6.5 | 1.0% | Dec 10, 2021 | IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a s... |
| CVE-2021-36911 | MEDIUM | 5.4 | 0.6% | Dec 10, 2021 | Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), cou... |
| CVE-2021-3829 | MEDIUM | 6.1 | 0.8% | Dec 10, 2021 | openwhyd is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-40834 | MEDIUM | 4.3 | 0.7% | Dec 10, 2021 | A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a special... |
| CVE-2021-37187 | MEDIUM | 6.5 | 0.7% | Dec 10, 2021 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file... |
| CVE-2021-4084 | MEDIUM | 6.1 | 1.6% | Dec 10, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4082 | MEDIUM | 4.3 | 0.4% | Dec 10, 2021 | pimcore is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4081 | MEDIUM | 6.1 | 0.8% | Dec 10, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4033 | MEDIUM | 6.5 | 0.5% | Dec 9, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-43797 | MEDIUM | 6.5 | 2.7% | Dec 9, 2021 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan... |
| CVE-2021-38931 | MEDIUM | 6.5 | 1.2% | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclos... |
| CVE-2021-38926 | MEDIUM | 5.5 | 0.3% | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2021-4038 | MEDIUM | 4.8 | 0.6% | Dec 9, 2021 | Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote ... |
| CVE-2021-41697 | MEDIUM | 6.1 | 0.7% | Dec 9, 2021 | A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description pa... |
| CVE-2021-41696 | MEDIUM | 6.5 | 0.9% | Dec 9, 2021 | An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password r... |
| CVE-2021-20137 | MEDIUM | 6.1 | 2.6% | Dec 9, 2021 | A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the... |
| CVE-2021-22565 | MEDIUM | 6.5 | 0.4% | Dec 9, 2021 | An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable t... |
| CVE-2021-42759 | MEDIUM | 6.7 | 0.3% | Dec 9, 2021 | A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows atta... |
| CVE-2021-36167 | MEDIUM | 5.3 | 0.6% | Dec 9, 2021 | An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 an... |
| CVE-2021-43410 | MEDIUM | 5.3 | 2.4% | Dec 9, 2021 | Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log statements. In particular, some ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now