2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34081 | HIGH | 8.8 | 3.6% | Jun 2, 2022 | OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via ... |
| CVE-2021-34080 | CRITICAL | 9.8 | 3.2% | Jun 2, 2022 | OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands v... |
| CVE-2021-34079 | CRITICAL | 9.8 | 4.2% | Jun 2, 2022 | OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands ... |
| CVE-2021-34078 | HIGH | 8.8 | 2.5% | Jun 2, 2022 | lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scan... |
| CVE-2021-33615 | HIGH | 7.5 | 1.2% | Jun 2, 2022 | RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type. |
| CVE-2021-33504 | MEDIUM | 4.9 | 0.7% | Jun 2, 2022 | Couchbase Server before 7.1.0 has Incorrect Access Control. |
| CVE-2021-33254 | HIGH | 7.5 | 1.5% | Jun 2, 2022 | An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a d... |
| CVE-2021-32546 | HIGH | 8.8 | 2.0% | Jun 2, 2022 | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely... |
| CVE-2021-26635 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target... |
| CVE-2021-26634 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and... |
| CVE-2021-26633 | CRITICAL | 9.8 | 0.8% | Jun 2, 2022 | SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege esc... |
| CVE-2021-27914 | MEDIUM | 4.8 | 0.4% | Jun 1, 2022 | A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject exe... |
| CVE-2021-27778 | MEDIUM | 4.8 | 0.4% | Jun 1, 2022 | HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Appro... |
| CVE-2021-3555 | HIGH | 8.8 | 0.7% | May 31, 2022 | A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to ... |
| CVE-2021-27781 | MEDIUM | 4.8 | 0.4% | May 27, 2022 | The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. |
| CVE-2021-27780 | MEDIUM | 5.3 | 0.7% | May 27, 2022 | The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment. |
| CVE-2021-28509 | MEDIUM | 6.1 | 0.4% | May 26, 2022 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te... |
| CVE-2021-28508 | MEDIUM | 6.1 | 0.5% | May 26, 2022 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te... |
| CVE-2021-4232 | MEDIUM | 6.1 | 0.5% | May 26, 2022 | A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function o... |
| CVE-2021-33016 | CRITICAL | 9.8 | 0.9% | May 26, 2022 | An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 co... |
| CVE-2021-33014 | HIGH | 8.8 | 0.8% | May 26, 2022 | An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versio... |
| CVE-2021-4231 | MEDIUM | 5.4 | 1.1% | May 26, 2022 | A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the ... |
| CVE-2021-34360 | HIGH | 8.8 | 0.4% | May 26, 2022 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If explo... |
| CVE-2021-40317 | HIGH | 8.8 | 0.9% | May 26, 2022 | Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter. |
| CVE-2021-42860 | HIGH | 7.5 | 1.0% | May 26, 2022 | A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it wil... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now