2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40334 | HIGH | 7.5 | 1.0% | Dec 2, 2021 | Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 all... |
| CVE-2021-40333 | HIGH | 7.1 | 0.6% | Dec 2, 2021 | Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access ... |
| CVE-2021-43795 | HIGH | 7.5 | 1.6% | Dec 2, 2021 | Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local ... |
| CVE-2021-23263 | HIGH | 7.5 | 1.6% | Dec 2, 2021 | Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and so... |
| CVE-2021-23262 | HIGH | 7.2 | 0.6% | Dec 2, 2021 | Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE. |
| CVE-2021-23259 | HIGH | 7.2 | 0.7% | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib... |
| CVE-2021-23258 | HIGH | 7.2 | 0.7% | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SP... |
| CVE-2021-44227 | HIGH | 8.8 | 0.7% | Dec 2, 2021 | In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that tok... |
| CVE-2021-42711 | HIGH | 7.8 | 0.3% | Dec 1, 2021 | Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This fil... |
| CVE-2021-43137 | HIGH | 8.8 | 0.5% | Dec 1, 2021 | Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via... |
| CVE-2021-41039 | HIGH | 7.5 | 1.3% | Dec 1, 2021 | In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property proper... |
| CVE-2021-38575 | HIGH | 8.1 | 1.9% | Dec 1, 2021 | NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. |
| CVE-2021-42776 | HIGH | 7.7 | 0.8% | Dec 1, 2021 | CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import. |
| CVE-2021-20400 | HIGH | 7.5 | 0.7% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h... |
| CVE-2021-44480 | HIGH | 8.1 | 1.0% | Dec 1, 2021 | Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen... |
| CVE-2021-20611 | HIGH | 7.5 | 3.0% | Dec 1, 2021 | Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/0... |
| CVE-2021-20610 | HIGH | 7.5 | 3.1% | Dec 1, 2021 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU... |
| CVE-2021-20609 | HIGH | 7.5 | 3.1% | Dec 1, 2021 | Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Seri... |
| CVE-2021-32592 | HIGH | 7.8 | 0.2% | Dec 1, 2021 | An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0,... |
| CVE-2021-4017 | HIGH | 8.8 | 0.6% | Dec 1, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3984 | HIGH | 7.8 | 1.5% | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-4019 | HIGH | 7.8 | 1.8% | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-34599 | HIGH | 7.4 | 0.5% | Dec 1, 2021 | Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS ... |
| CVE-2021-20864 | HIGH | 8.8 | 0.5% | Dec 1, 2021 | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v... |
| CVE-2021-20863 | HIGH | 8 | 0.9% | Dec 1, 2021 | OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.2... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now