2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25002 | HIGH | 7.5 | 1.4% | May 2, 2022 | The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which co... |
| CVE-2021-32500 | — | — | — | May 2, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-4200 | MEDIUM | 5.4 | 0.6% | May 2, 2022 | A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restr... |
| CVE-2021-46790 | HIGH | 7.8 | 0.5% | May 2, 2022 | ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream positi... |
| CVE-2021-36784 | HIGH | 7.2 | 0.8% | May 2, 2022 | A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to... |
| CVE-2021-36778 | HIGH | 7.5 | 0.7% | May 2, 2022 | A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather cred... |
| CVE-2021-40822 | HIGH | 7.5 | 18.9% | May 2, 2022 | GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host. |
| CVE-2021-31674 | MEDIUM | 6.1 | 3.8% | May 2, 2022 | Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacke... |
| CVE-2021-31673 | MEDIUM | 6.1 | 3.4% | May 2, 2022 | A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo... |
| CVE-2021-42001 | CRITICAL | 9.9 | 0.5% | Apr 30, 2022 | PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposu... |
| CVE-2021-41994 | MEDIUM | 4.8 | 0.2% | Apr 30, 2022 | A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to a... |
| CVE-2021-41993 | MEDIUM | 4.8 | 0.2% | Apr 30, 2022 | A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading ... |
| CVE-2021-41992 | MEDIUM | 5.6 | 0.5% | Apr 30, 2022 | A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading... |
| CVE-2021-4207 | HIGH | 8.2 | 0.4% | Apr 29, 2022 | A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.... |
| CVE-2021-4206 | HIGH | 8.2 | 0.8% | Apr 29, 2022 | A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lea... |
| CVE-2021-3982 | MEDIUM | 5.5 | 0.3% | Apr 29, 2022 | Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with... |
| CVE-2021-36207 | HIGH | 8.8 | 0.9% | Apr 29, 2022 | Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow ... |
| CVE-2021-43938 | CRITICAL | 9.8 | 1.0% | Apr 29, 2022 | Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server witho... |
| CVE-2021-43937 | HIGH | 8.8 | 0.3% | Apr 29, 2022 | Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, c... |
| CVE-2021-39082 | HIGH | 7.5 | 0.6% | Apr 29, 2022 | IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to de... |
| CVE-2021-41948 | MEDIUM | 5.4 | 0.5% | Apr 29, 2022 | A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List ... |
| CVE-2021-44596 | CRITICAL | 9.8 | 22.7% | Apr 29, 2022 | Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an ... |
| CVE-2021-44595 | HIGH | 8.8 | 21.0% | Apr 29, 2022 | Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m... |
| CVE-2021-41942 | HIGH | 7.5 | 1.1% | Apr 29, 2022 | The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sens... |
| CVE-2021-38952 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now