2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27836 | MEDIUM | 6.5 | 1.1% | Nov 3, 2021 | An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial o... |
| CVE-2021-43324 | MEDIUM | 6.1 | 0.6% | Nov 3, 2021 | LibreNMS through 21.10.2 allows XSS via a widget title. |
| CVE-2021-36698 | MEDIUM | 5.4 | 0.7% | Nov 3, 2021 | Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name. |
| CVE-2021-36697 | MEDIUM | 6.7 | 0.4% | Nov 3, 2021 | With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component... |
| CVE-2021-33209 | MEDIUM | 5.3 | 0.7% | Nov 3, 2021 | An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether ... |
| CVE-2021-33210 | MEDIUM | 4.3 | 0.8% | Nov 3, 2021 | An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information w... |
| CVE-2021-39237 | MEDIUM | 4.6 | 2.4% | Nov 3, 2021 | Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential i... |
| CVE-2021-38502 | MEDIUM | 5.9 | 1.1% | Nov 3, 2021 | Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgr... |
| CVE-2021-38497 | MEDIUM | 6.5 | 0.5% | Nov 3, 2021 | Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another o... |
| CVE-2021-38492 | MEDIUM | 6.5 | 1.1% | Nov 3, 2021 | When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to... |
| CVE-2021-38491 | MEDIUM | 6.5 | 0.9% | Nov 3, 2021 | Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerabil... |
| CVE-2021-20135 | MEDIUM | 6.7 | 0.3% | Nov 3, 2021 | Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an... |
| CVE-2021-43265 | MEDIUM | 5.4 | 0.6% | Nov 2, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT ... |
| CVE-2021-37996 | MEDIUM | 5.5 | 0.6% | Nov 2, 2021 | Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to... |
| CVE-2021-37995 | MEDIUM | 6.5 | 0.8% | Nov 2, 2021 | Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to pot... |
| CVE-2021-37994 | MEDIUM | 6.5 | 0.8% | Nov 2, 2021 | Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypas... |
| CVE-2021-37990 | MEDIUM | 5.5 | 0.6% | Nov 2, 2021 | Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to l... |
| CVE-2021-37989 | MEDIUM | 6.5 | 0.8% | Nov 2, 2021 | Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content ... |
| CVE-2021-42754 | MEDIUM | 5 | 0.4% | Nov 2, 2021 | An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 ... |
| CVE-2021-41023 | MEDIUM | 5.5 | 0.2% | Nov 2, 2021 | A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated... |
| CVE-2021-36184 | MEDIUM | 6.5 | 1.0% | Nov 2, 2021 | A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-36176 | MEDIUM | 6.1 | 0.6% | Nov 2, 2021 | Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a ... |
| CVE-2021-41019 | MEDIUM | 6.5 | 0.6% | Nov 2, 2021 | An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may... |
| CVE-2021-32595 | MEDIUM | 6.5 | 0.8% | Nov 2, 2021 | Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a ... |
| CVE-2021-26107 | MEDIUM | 4.3 | 0.5% | Nov 2, 2021 | An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now