2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21946 | HIGH | 8.8 | 1.0% | Apr 14, 2022 | Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Ac... |
| CVE-2021-21945 | HIGH | 8.8 | 1.0% | Apr 14, 2022 | Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A spe... |
| CVE-2021-21944 | HIGH | 8.8 | 1.0% | Apr 14, 2022 | Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A spe... |
| CVE-2021-21943 | HIGH | 8.8 | 1.5% | Apr 14, 2022 | A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A special... |
| CVE-2021-21942 | HIGH | 8.8 | 1.8% | Apr 14, 2022 | An out-of-bounds write vulnerability exists in the TIFF YCbCr image parser functionality of Accusoft ImageGear 19.10. A ... |
| CVE-2021-21939 | HIGH | 8.8 | 1.5% | Apr 14, 2022 | A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A special... |
| CVE-2021-21938 | HIGH | 8.8 | 1.7% | Apr 14, 2022 | A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A... |
| CVE-2021-21914 | HIGH | 8.8 | 1.5% | Apr 14, 2022 | A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10... |
| CVE-2021-45228 | MEDIUM | 5.4 | 0.6% | Apr 14, 2022 | An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the d... |
| CVE-2021-45227 | MEDIUM | 5.4 | 0.6% | Apr 14, 2022 | An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file... |
| CVE-2021-43633 | MEDIUM | 5.4 | 0.5% | Apr 14, 2022 | Sourcecodester Messaging Web Application 1.0 is vulnerable to stored XSS. If a sender inserts valid scripts into the cha... |
| CVE-2021-43290 | CRITICAL | 9.8 | 3.2% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma... |
| CVE-2021-43289 | HIGH | 7.5 | 2.3% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma... |
| CVE-2021-43288 | MEDIUM | 5.4 | 0.9% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious J... |
| CVE-2021-43286 | HIGH | 8.8 | 2.6% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a Go... |
| CVE-2021-43287 | HIGH | 7.5 | 23.7% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,... |
| CVE-2021-43154 | MEDIUM | 6.1 | 0.5% | Apr 13, 2022 | Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action i... |
| CVE-2021-41119 | HIGH | 7.5 | 1.5% | Apr 13, 2022 | Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial o... |
| CVE-2021-42136 | CRITICAL | 9 | 4.5% | Apr 13, 2022 | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows... |
| CVE-2021-22797 | HIGH | 7.8 | 26.1% | Apr 13, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could ... |
| CVE-2021-22795 | CRITICAL | 9.8 | 3.1% | Apr 13, 2022 | A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists... |
| CVE-2021-22794 | CRITICAL | 9.8 | 2.1% | Apr 13, 2022 | A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ... |
| CVE-2021-46167 | HIGH | 7.8 | 0.4% | Apr 13, 2022 | An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data an... |
| CVE-2021-43741 | CRITICAL | 9.8 | 4.5% | Apr 13, 2022 | CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicio... |
| CVE-2021-43742 | MEDIUM | 5.4 | 0.5% | Apr 13, 2022 | CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now