2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43282 | MEDIUM | 6.5 | 0.7% | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone with... |
| CVE-2021-22095 | MEDIUM | 6.5 | 1.0% | Nov 30, 2021 | In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, wil... |
| CVE-2021-39000 | MEDIUM | 5.5 | 0.6% | Nov 30, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensiti... |
| CVE-2021-38999 | MEDIUM | 5.5 | 0.2% | Nov 30, 2021 | IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trac... |
| CVE-2021-38967 | MEDIUM | 6.7 | 0.3% | Nov 30, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Forc... |
| CVE-2021-38958 | MEDIUM | 5.5 | 0.2% | Nov 30, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force... |
| CVE-2021-43998 | MEDIUM | 6.5 | 1.0% | Nov 30, 2021 | HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-cr... |
| CVE-2021-25987 | MEDIUM | 4.6 | 0.3% | Nov 30, 2021 | Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious java... |
| CVE-2021-42122 | MEDIUM | 4.3 | 0.7% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42121 | MEDIUM | 4.3 | 1.0% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42120 | MEDIUM | 6.5 | 1.1% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42119 | MEDIUM | 5.4 | 0.5% | Nov 30, 2021 | Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version... |
| CVE-2021-42118 | MEDIUM | 5.4 | 0.7% | Nov 30, 2021 | Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version... |
| CVE-2021-42117 | MEDIUM | 5.4 | 0.7% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42116 | MEDIUM | 4.3 | 0.8% | Nov 30, 2021 | Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1... |
| CVE-2021-43788 | MEDIUM | 5 | 25.8% | Nov 29, 2021 | Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that... |
| CVE-2021-43787 | MEDIUM | 6.1 | 1.3% | Nov 29, 2021 | Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the u... |
| CVE-2021-44203 | MEDIUM | 5.4 | 0.5% | Nov 29, 2021 | Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis ... |
| CVE-2021-44202 | MEDIUM | 5.4 | 0.5% | Nov 29, 2021 | Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber P... |
| CVE-2021-44201 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Prot... |
| CVE-2021-44200 | MEDIUM | 5.4 | 0.5% | Nov 29, 2021 | Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect... |
| CVE-2021-44199 | MEDIUM | 5.5 | 0.2% | Nov 29, 2021 | DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) b... |
| CVE-2021-42365 | MEDIUM | 4.8 | 0.7% | Nov 29, 2021 | The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the na... |
| CVE-2021-3802 | MEDIUM | 4.2 | 0.8% | Nov 29, 2021 | A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to ke... |
| CVE-2021-39995 | MEDIUM | 6.5 | 0.6% | Nov 29, 2021 | Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now