2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29396 | CRITICAL | 9.8 | 1.6% | Feb 4, 2022 | Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated ... |
| CVE-2021-29395 | HIGH | 7.5 | 1.8% | Feb 4, 2022 | Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 al... |
| CVE-2021-29394 | MEDIUM | 6.5 | 0.8% | Feb 4, 2022 | Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 all... |
| CVE-2021-29393 | CRITICAL | 9.8 | 3.4% | Feb 4, 2022 | Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allo... |
| CVE-2021-43635 | MEDIUM | 6.1 | 1.7% | Feb 4, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malic... |
| CVE-2021-46398 | HIGH | 8.8 | 6.7% | Feb 4, 2022 | A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor use... |
| CVE-2021-44978 | CRITICAL | 9.8 | 2.1% | Feb 4, 2022 | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code ... |
| CVE-2021-44977 | HIGH | 7.5 | 1.6% | Feb 4, 2022 | In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. |
| CVE-2021-44886 | MEDIUM | 5.3 | 0.9% | Feb 4, 2022 | In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't h... |
| CVE-2021-43145 | HIGH | 8.1 | 0.9% | Feb 4, 2022 | With certain LDAP configurations, Zammad 5.0.1 was found to be vulnerable to unauthorized access with existing user acco... |
| CVE-2021-44983 | MEDIUM | 4.9 | 1.1% | Feb 4, 2022 | In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Manage... |
| CVE-2021-46320 | HIGH | 7.5 | 1.2% | Feb 4, 2022 | In OpenZeppelin <=v4.4.0, initializer functions that are invoked separate from contract creation (the most prominent exa... |
| CVE-2021-44903 | HIGH | 7.8 | 0.3% | Feb 4, 2022 | Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabi... |
| CVE-2021-44901 | HIGH | 7.8 | 0.5% | Feb 4, 2022 | Micro-Star International (MSI) Dragon Center <= 2.0.116.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulne... |
| CVE-2021-44900 | HIGH | 7.8 | 0.3% | Feb 4, 2022 | Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulne... |
| CVE-2021-44899 | HIGH | 7.8 | 0.4% | Feb 4, 2022 | Micro-Star International (MSI) Center <= 1.0.31.0 is vulnerable to multiple Privilege Escalation vulnerabilities in the ... |
| CVE-2021-46457 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgS... |
| CVE-2021-46456 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetW... |
| CVE-2021-46455 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetS... |
| CVE-2021-46454 | CRITICAL | 9.8 | 4.8% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetW... |
| CVE-2021-46453 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetS... |
| CVE-2021-46452 | CRITICAL | 9.8 | 4.1% | Feb 4, 2022 | D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetN... |
| CVE-2021-46233 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_... |
| CVE-2021-46232 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function vers... |
| CVE-2021-46231 | CRITICAL | 9.8 | 4.0% | Feb 4, 2022 | D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now