2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20007 | — | — | — | Feb 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-20006 | — | — | — | Feb 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-20005 | — | — | — | Feb 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-20004 | — | — | — | Feb 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-20003 | — | — | — | Feb 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-20002 | — | — | — | Feb 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-3813 | MEDIUM | 6.5 | 1.1% | Feb 9, 2022 | Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. |
| CVE-2021-46360 | HIGH | 8.8 | 9.2% | Feb 9, 2022 | Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar... |
| CVE-2021-46354 | HIGH | 7.5 | 15.6% | Feb 9, 2022 | Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vuln... |
| CVE-2021-40837 | MEDIUM | 5.3 | 0.6% | Feb 9, 2022 | A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompr... |
| CVE-2021-25939 | LOW | 2.7 | 1.1% | Feb 9, 2022 | In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a public... |
| CVE-2021-37852 | HIGH | 7.8 | 0.6% | Feb 9, 2022 | ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attack... |
| CVE-2021-45919 | MEDIUM | 5.4 | 0.6% | Feb 8, 2022 | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. |
| CVE-2021-45329 | MEDIUM | 6.1 | 0.8% | Feb 8, 2022 | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wi... |
| CVE-2021-45328 | MEDIUM | 6.1 | 1.0% | Feb 8, 2022 | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. |
| CVE-2021-45327 | CRITICAL | 9.8 | 2.1% | Feb 8, 2022 | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable a... |
| CVE-2021-45326 | HIGH | 8.8 | 0.6% | Feb 8, 2022 | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especi... |
| CVE-2021-45325 | HIGH | 7.5 | 1.0% | Feb 8, 2022 | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL. |
| CVE-2021-44957 | MEDIUM | 6.5 | 0.8% | Feb 8, 2022 | Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in th... |
| CVE-2021-44956 | MEDIUM | 6.5 | 0.8% | Feb 8, 2022 | Two Heap based buffer overflow vulnerabilities exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23852. Issu... |
| CVE-2021-44864 | MEDIUM | 6.5 | 10.2% | Feb 8, 2022 | TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash rou... |
| CVE-2021-20877 | MEDIUM | 4.8 | 0.8% | Feb 8, 2022 | Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF... |
| CVE-2021-45281 | MEDIUM | 6.1 | 0.7% | Feb 7, 2022 | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the us... |
| CVE-2021-3861 | MEDIUM | 6.8 | 0.5% | Feb 7, 2022 | The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer... |
| CVE-2021-3835 | HIGH | 8.8 | 0.7% | Feb 7, 2022 | Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now