2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37777 | HIGH | 7.5 | 1.6% | Oct 4, 2021 | Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visib... |
| CVE-2021-36051 | HIGH | 7.8 | 5.4% | Oct 4, 2021 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arb... |
| CVE-2021-24465 | HIGH | 8.1 | 1.1% | Oct 4, 2021 | The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery sh... |
| CVE-2021-22557 | HIGH | 7.8 | 1.6% | Oct 4, 2021 | SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within ... |
| CVE-2021-41869 | HIGH | 8.8 | 1.5% | Oct 4, 2021 | SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation. |
| CVE-2021-41322 | HIGH | 8.8 | 1.6% | Oct 4, 2021 | Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 dur... |
| CVE-2021-41285 | HIGH | 7.8 | 0.5% | Oct 4, 2021 | Ballistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vuln... |
| CVE-2021-40325 | HIGH | 7.5 | 1.3% | Oct 4, 2021 | Cobbler before 3.3.0 allows authorization bypass for modification of settings. |
| CVE-2021-40324 | HIGH | 7.5 | 68.6% | Oct 4, 2021 | Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. |
| CVE-2021-41864 | HIGH | 7.8 | 0.4% | Oct 2, 2021 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to tri... |
| CVE-2021-41847 | HIGH | 8.8 | 1.5% | Oct 1, 2021 | An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with ... |
| CVE-2021-38110 | HIGH | 7.8 | 2.1% | Oct 1, 2021 | Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsin... |
| CVE-2021-38101 | HIGH | 7.8 | 2.1% | Oct 1, 2021 | CDRRip.dll in Corel PhotoPaint Standard 2020 22.0.0.474 is affected by an Out-of-bounds Write vulnerability when parsing... |
| CVE-2021-38100 | HIGH | 7.8 | 2.1% | Oct 1, 2021 | Corel PhotoPaint Standard 2020 22.0.0.474 is affected by an Out-of-bounds Write vulnerability when parsing a crafted fil... |
| CVE-2021-38098 | HIGH | 7.8 | 2.3% | Oct 1, 2021 | Corel PDF Fusion 2.6.2.0 is affected by a Heap Corruption vulnerability when parsing a crafted file. An unauthenticated ... |
| CVE-2021-38103 | HIGH | 7.8 | 2.3% | Oct 1, 2021 | IBJPG2.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsing a cra... |
| CVE-2021-38099 | HIGH | 7.8 | 2.3% | Oct 1, 2021 | CDRRip.dll in Corel PhotoPaint Standard 2020 22.0.0.474 is affected by an Out-of-bounds Write vulnerability when parsing... |
| CVE-2021-38096 | HIGH | 7.8 | 3.0% | Oct 1, 2021 | Coreip.dll in Corel PDF Fusion 2.6.2.0 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. ... |
| CVE-2021-38097 | HIGH | 7.8 | 2.7% | Oct 1, 2021 | Corel PDF Fusion 2.6.2.0 is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthentic... |
| CVE-2021-29108 | HIGH | 8.8 | 0.8% | Oct 1, 2021 | There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 a... |
| CVE-2021-41648 | HIGH | 7.5 | 10.0% | Oct 1, 2021 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId ... |
| CVE-2021-35297 | HIGH | 7.8 | 1.2% | Oct 1, 2021 | Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that trig... |
| CVE-2021-41459 | HIGH | 7.5 | 1.2% | Oct 1, 2021 | There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function s... |
| CVE-2021-41457 | HIGH | 7.5 | 1.2% | Oct 1, 2021 | There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a deni... |
| CVE-2021-41456 | HIGH | 7.5 | 1.2% | Oct 1, 2021 | There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function s... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now