2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42712 | HIGH | 7.8 | 0.3% | Feb 15, 2022 | Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. |
| CVE-2021-41552 | HIGH | 8.8 | 0.7% | Feb 15, 2022 | CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection. |
| CVE-2021-46558 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to e... |
| CVE-2021-46557 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs. |
| CVE-2021-43948 | MEDIUM | 4.3 | 0.8% | Feb 15, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi... |
| CVE-2021-43941 | MEDIUM | 6.5 | 0.6% | Feb 15, 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including... |
| CVE-2021-43940 | HIGH | 7.8 | 0.3% | Feb 15, 2022 | Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated... |
| CVE-2021-43953 | MEDIUM | 4.3 | 0.5% | Feb 15, 2022 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread C... |
| CVE-2021-43950 | MEDIUM | 4.3 | 0.8% | Feb 15, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi... |
| CVE-2021-43952 | MEDIUM | 4.3 | 0.4% | Feb 15, 2022 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default... |
| CVE-2021-4201 | CRITICAL | 9.8 | 1.9% | Feb 14, 2022 | Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthen... |
| CVE-2021-46463 | CRITICAL | 9.8 | 1.6% | Feb 14, 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerabili... |
| CVE-2021-46462 | HIGH | 7.5 | 1.7% | Feb 14, 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /sr... |
| CVE-2021-46461 | CRITICAL | 9.8 | 3.1% | Feb 14, 2022 | njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/... |
| CVE-2021-45005 | CRITICAL | 9.8 | 1.4% | Feb 14, 2022 | Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested t... |
| CVE-2021-45310 | MEDIUM | 5.3 | 0.9% | Feb 14, 2022 | Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to ... |
| CVE-2021-45348 | HIGH | 7.5 | 0.9% | Feb 14, 2022 | An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv paramete... |
| CVE-2021-43106 | MEDIUM | 6.1 | 0.7% | Feb 14, 2022 | A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.3... |
| CVE-2021-45347 | HIGH | 7.5 | 1.1% | Feb 14, 2022 | An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by chan... |
| CVE-2021-45346 | MEDIUM | 4.3 | 1.6% | Feb 14, 2022 | A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made... |
| CVE-2021-39080 | MEDIUM | 6.5 | 0.7% | Feb 14, 2022 | Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could... |
| CVE-2021-39079 | MEDIUM | 5.4 | 0.5% | Feb 14, 2022 | IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This... |
| CVE-2021-45392 | HIGH | 7.5 | 12.3% | Feb 14, 2022 | A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/s... |
| CVE-2021-46371 | HIGH | 7.5 | 4.4% | Feb 14, 2022 | antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the... |
| CVE-2021-45421 | HIGH | 7.5 | 1.6% | Feb 14, 2022 | Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now