2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3872 | HIGH | 7.8 | 1.4% | Oct 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3869 | HIGH | 7.5 | 1.3% | Oct 19, 2021 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2021-3858 | HIGH | 8.8 | 0.5% | Oct 19, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3846 | HIGH | 8.8 | 0.8% | Oct 19, 2021 | firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-38486 | HIGH | 8.5 | 0.8% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the aff... |
| CVE-2021-38484 | HIGH | 7.2 | 2.6% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or... |
| CVE-2021-38480 | HIGH | 8.8 | 0.5% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when un... |
| CVE-2021-38464 | HIGH | 7.4 | 0.3% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow... |
| CVE-2021-42261 | HIGH | 7.5 | 2.2% | Oct 19, 2021 | Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation coul... |
| CVE-2021-36512 | HIGH | 7.5 | 0.9% | Oct 19, 2021 | An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers t... |
| CVE-2021-41155 | HIGH | 8.8 | 1.5% | Oct 18, 2021 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi... |
| CVE-2021-41154 | HIGH | 8.8 | 1.5% | Oct 18, 2021 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi... |
| CVE-2021-41152 | HIGH | 7.7 | 1.2% | Oct 18, 2021 | OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning man... |
| CVE-2021-36513 | HIGH | 7.5 | 1.8% | Oct 18, 2021 | An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may all... |
| CVE-2021-41971 | HIGH | 8.8 | 1.7% | Oct 18, 2021 | Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allow... |
| CVE-2021-42098 | HIGH | 8.8 | 1.6% | Oct 18, 2021 | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to byp... |
| CVE-2021-41991 | HIGH | 7.5 | 4.8% | Oct 18, 2021 | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests wi... |
| CVE-2021-41990 | HIGH | 7.5 | 6.4% | Oct 18, 2021 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS sig... |
| CVE-2021-24754 | HIGH | 7.2 | 1.3% | Oct 18, 2021 | The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it... |
| CVE-2021-24684 | HIGH | 8.8 | 4.3% | Oct 18, 2021 | The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary... |
| CVE-2021-38442 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38438 | HIGH | 7.8 | 1.0% | Oct 18, 2021 | A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid us... |
| CVE-2021-38436 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38434 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38430 | HIGH | 7.8 | 1.0% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now