2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24009 | HIGH | 8.8 | 1.5% | Apr 6, 2022 | Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of Fo... |
| CVE-2021-45104 | HIGH | 7.4 | 0.6% | Apr 6, 2022 | An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor net... |
| CVE-2021-40375 | MEDIUM | 6.5 | 1.6% | Apr 6, 2022 | Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having t... |
| CVE-2021-40374 | MEDIUM | 5.4 | 1.2% | Apr 6, 2022 | A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patien... |
| CVE-2021-30497 | HIGH | 7.5 | 96.6% | Apr 6, 2022 | Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal... |
| CVE-2021-45103 | HIGH | 8.1 | 0.9% | Apr 6, 2022 | An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S... |
| CVE-2021-41752 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due t... |
| CVE-2021-41751 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object... |
| CVE-2021-30080 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access contr... |
| CVE-2021-28428 | CRITICAL | 9.8 | 1.2% | Apr 5, 2022 | File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media... |
| CVE-2021-27117 | HIGH | 7.8 | 0.4% | Apr 5, 2022 | An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch ... |
| CVE-2021-27116 | HIGH | 7.8 | 0.4% | Apr 5, 2022 | An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlin... |
| CVE-2021-41245 | HIGH | 8.1 | 0.7% | Apr 5, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `... |
| CVE-2021-38834 | HIGH | 8.8 | 2.0% | Apr 5, 2022 | easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through ... |
| CVE-2021-39114 | HIGH | 8.8 | 1.7% | Apr 5, 2022 | Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data C... |
| CVE-2021-33207 | CRITICAL | 9.8 | 1.6% | Apr 5, 2022 | The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570... |
| CVE-2021-45893 | HIGH | 7.5 | 1.6% | Apr 5, 2022 | An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes... |
| CVE-2021-45892 | MEDIUM | 5.9 | 0.8% | Apr 5, 2022 | An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format. |
| CVE-2021-45891 | HIGH | 8.8 | 1.4% | Apr 5, 2022 | An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the ap... |
| CVE-2021-44109 | HIGH | 7.5 | 1.6% | Apr 5, 2022 | A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a c... |
| CVE-2021-44108 | HIGH | 7.5 | 1.5% | Apr 5, 2022 | A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of S... |
| CVE-2021-43008 | HIGH | 7.5 | 13.6% | Apr 5, 2022 | Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbit... |
| CVE-2021-42324 | HIGH | 7.4 | 0.6% | Apr 5, 2022 | An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper paramete... |
| CVE-2021-45894 | MEDIUM | 5.9 | 0.8% | Apr 5, 2022 | An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information. |
| CVE-2021-36851 | MEDIUM | 5.4 | 0.5% | Apr 4, 2022 | Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now