2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44209 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. |
| CVE-2021-44208 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. |
| CVE-2021-26601 | HIGH | 8.1 | 3.2% | Mar 28, 2022 | ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal. |
| CVE-2021-26600 | CRITICAL | 9.8 | 5.5% | Mar 28, 2022 | ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= inste... |
| CVE-2021-26599 | CRITICAL | 9.8 | 19.4% | Mar 28, 2022 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. |
| CVE-2021-26598 | MEDIUM | 5.3 | 10.8% | Mar 28, 2022 | ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta... |
| CVE-2021-44127 | CRITICAL | 9.8 | 3.3% | Mar 27, 2022 | In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execut... |
| CVE-2021-40906 | MEDIUM | 6.1 | 1.0% | Mar 25, 2022 | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in... |
| CVE-2021-40905 | HIGH | 8.8 | 3.2% | Mar 25, 2022 | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uplo... |
| CVE-2021-40904 | HIGH | 8.8 | 3.8% | Mar 25, 2022 | The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dok... |
| CVE-2021-44683 | HIGH | 8.2 | 1.0% | Mar 25, 2022 | The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open functi... |
| CVE-2021-44905 | HIGH | 8.2 | 1.3% | Mar 25, 2022 | Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attac... |
| CVE-2021-4203 | MEDIUM | 6.8 | 1.8% | Mar 25, 2022 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race w... |
| CVE-2021-4202 | HIGH | 7 | 0.4% | Mar 25, 2022 | A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kern... |
| CVE-2021-4157 | HIGH | 8 | 1.6% | Mar 25, 2022 | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users... |
| CVE-2021-4147 | MEDIUM | 6.5 | 0.2% | Mar 25, 2022 | A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on t... |
| CVE-2021-44768 | MEDIUM | 5.5 | 0.7% | Mar 25, 2022 | Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specifi... |
| CVE-2021-44477 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD paramete... |
| CVE-2021-44462 | HIGH | 7.1 | 0.7% | Mar 25, 2022 | This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionR... |
| CVE-2021-3941 | MEDIUM | 6.5 | 0.3% | Mar 25, 2022 | In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x -... |
| CVE-2021-3933 | MEDIUM | 5.5 | 0.8% | Mar 25, 2022 | An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could caus... |
| CVE-2021-3814 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut... |
| CVE-2021-3582 | MEDIUM | 6.5 | 0.4% | Mar 25, 2022 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRD... |
| CVE-2021-3567 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-... |
| CVE-2021-3422 | HIGH | 7.5 | 0.6% | Mar 25, 2022 | The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk En... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now