2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3964 | MEDIUM | 5.9 | 0.8% | Dec 1, 2021 | elgg is vulnerable to Authorization Bypass Through User-Controlled Key |
| CVE-2021-4015 | MEDIUM | 4.3 | 0.4% | Dec 1, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3993 | MEDIUM | 6.5 | 0.5% | Dec 1, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3992 | MEDIUM | 6.5 | 1.0% | Dec 1, 2021 | kimai2 is vulnerable to Improper Access Control |
| CVE-2021-3990 | MEDIUM | 6.5 | 0.9% | Dec 1, 2021 | showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
| CVE-2021-3989 | MEDIUM | 6.1 | 0.8% | Dec 1, 2021 | showdoc is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-4018 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-20862 | MEDIUM | 4.3 | 0.4% | Dec 1, 2021 | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v... |
| CVE-2021-20858 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenti... |
| CVE-2021-20857 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenti... |
| CVE-2021-20856 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware ... |
| CVE-2021-20855 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware ... |
| CVE-2021-20854 | MEDIUM | 6.8 | 0.4% | Dec 1, 2021 | ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-ad... |
| CVE-2021-20853 | MEDIUM | 6.8 | 0.4% | Dec 1, 2021 | ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-ad... |
| CVE-2021-20852 | MEDIUM | 6.8 | 0.5% | Dec 1, 2021 | Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02... |
| CVE-2021-20847 | MEDIUM | 6.1 | 0.8% | Dec 1, 2021 | Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, ... |
| CVE-2021-36329 | MEDIUM | 6.5 | 0.7% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malici... |
| CVE-2021-36327 | MEDIUM | 5.3 | 1.0% | Nov 30, 2021 | Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unaut... |
| CVE-2021-36326 | MEDIUM | 6.5 | 1.2% | Nov 30, 2021 | Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A... |
| CVE-2021-4026 | MEDIUM | 4.3 | 0.9% | Nov 30, 2021 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-42564 | MEDIUM | 5.4 | 0.7% | Nov 30, 2021 | An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (wit... |
| CVE-2021-31787 | MEDIUM | 6.5 | 0.5% | Nov 30, 2021 | The Bluetooth Classic implementation on Actions ATS2815 chipsets does not properly handle the reception of continuous un... |
| CVE-2021-44230 | MEDIUM | 6.5 | 1.0% | Nov 30, 2021 | PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 databa... |
| CVE-2021-43295 | MEDIUM | 6.1 | 2.7% | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. |
| CVE-2021-43294 | MEDIUM | 6.1 | 1.0% | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now