2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32927 | MEDIUM | 6.1 | 0.6% | Apr 22, 2022 | An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS T... |
| CVE-2021-43708 | MEDIUM | 5.5 | 0.3% | Apr 21, 2022 | The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification l... |
| CVE-2021-35229 | MEDIUM | 6.1 | 3.0% | Apr 21, 2022 | Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when usi... |
| CVE-2021-23055 | MEDIUM | 6.5 | 0.7% | Apr 21, 2022 | On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ing... |
| CVE-2021-41162 | MEDIUM | 6.1 | 0.6% | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?opera... |
| CVE-2021-41161 | MEDIUM | 6.1 | 0.6% | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't prope... |
| CVE-2021-43481 | CRITICAL | 9.8 | 5.5% | Apr 20, 2022 | An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag... |
| CVE-2021-37740 | HIGH | 7.5 | 4.6% | Apr 20, 2022 | A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP inter... |
| CVE-2021-43990 | MEDIUM | 5.3 | 0.6% | Apr 20, 2022 | The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload... |
| CVE-2021-43988 | MEDIUM | 5.9 | 0.8% | Apr 20, 2022 | The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of fi... |
| CVE-2021-43986 | HIGH | 7 | 0.2% | Apr 20, 2022 | The setup program for the affected product configures its files and folders with full access, which may allow unauthoriz... |
| CVE-2021-43933 | MEDIUM | 5.9 | 0.6% | Apr 20, 2022 | The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receivin... |
| CVE-2021-38483 | MEDIUM | 5.7 | 0.2% | Apr 20, 2022 | The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileg... |
| CVE-2021-3101 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow... |
| CVE-2021-3100 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM be... |
| CVE-2021-4096 | HIGH | 8.8 | 0.6% | Apr 19, 2022 | The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla... |
| CVE-2021-26627 | HIGH | 7.5 | 1.3% | Apr 19, 2022 | Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerabilit... |
| CVE-2021-26626 | HIGH | 8.8 | 1.2% | Apr 19, 2022 | Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the s... |
| CVE-2021-26625 | HIGH | 8.8 | 0.6% | Apr 19, 2022 | Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platfor... |
| CVE-2021-23283 | MEDIUM | 5.4 | 0.5% | Apr 19, 2022 | Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerab... |
| CVE-2021-39078 | MEDIUM | 4.4 | 0.1% | Apr 19, 2022 | IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM... |
| CVE-2021-39076 | HIGH | 7.5 | 0.5% | Apr 19, 2022 | IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to d... |
| CVE-2021-39072 | MEDIUM | 5.9 | 1.2% | Apr 19, 2022 | IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to prope... |
| CVE-2021-39033 | MEDIUM | 6.5 | 1.0% | Apr 19, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote at... |
| CVE-2021-44519 | HIGH | 8.8 | 2.6% | Apr 19, 2022 | In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to re... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now