2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42645 | CRITICAL | 10 | 4.2% | May 10, 2022 | CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker... |
| CVE-2021-42581 | CRITICAL | 9.1 | 1.3% | May 10, 2022 | Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or av... |
| CVE-2021-41545 | HIGH | 7.5 | 0.9% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2021-43712 | MEDIUM | 5.4 | 0.9% | May 9, 2022 | Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker t... |
| CVE-2021-20479 | HIGH | 7.5 | 0.6% | May 9, 2022 | IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2021-23792 | CRITICAL | 9.8 | 1.0% | May 6, 2022 | The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injectio... |
| CVE-2021-23592 | CRITICAL | 9.8 | 1.6% | May 6, 2022 | The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unseria... |
| CVE-2021-27767 | HIGH | 7.8 | 0.2% | May 6, 2022 | The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that c... |
| CVE-2021-27766 | HIGH | 7.8 | 0.2% | May 6, 2022 | The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that co... |
| CVE-2021-27765 | HIGH | 7.8 | 0.3% | May 6, 2022 | The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability tha... |
| CVE-2021-27764 | MEDIUM | 6.5 | 0.5% | May 6, 2022 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie ... |
| CVE-2021-27762 | CRITICAL | 9.8 | 0.7% | May 6, 2022 | Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web ... |
| CVE-2021-27761 | HIGH | 7.5 | 0.3% | May 6, 2022 | Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks |
| CVE-2021-27760 | MEDIUM | 5.5 | 0.7% | May 6, 2022 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime c... |
| CVE-2021-27759 | MEDIUM | 6.5 | 0.3% | May 6, 2022 | This vulnerability arises because the application allows the user to perform some sensitive action without verifying tha... |
| CVE-2021-27758 | MEDIUM | 6.5 | 0.3% | May 6, 2022 | There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after... |
| CVE-2021-27751 | LOW | 3.3 | 0.2% | May 6, 2022 | HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circums... |
| CVE-2021-42743 | HIGH | 7.8 | 0.2% | May 6, 2022 | A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Sp... |
| CVE-2021-36912 | MEDIUM | 5.4 | 0.5% | May 6, 2022 | Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress,... |
| CVE-2021-33845 | MEDIUM | 5.3 | 0.8% | May 6, 2022 | The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerabilit... |
| CVE-2021-31559 | HIGH | 7.5 | 0.8% | May 6, 2022 | A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexe... |
| CVE-2021-26253 | HIGH | 8.1 | 0.7% | May 6, 2022 | A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in ... |
| CVE-2021-39027 | MEDIUM | 5 | 0.3% | May 6, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another componen... |
| CVE-2021-39023 | HIGH | 7.5 | 0.8% | May 6, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a ... |
| CVE-2021-25746 | HIGH | 7.1 | 1.3% | May 6, 2022 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadat... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now