2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42642 | HIGH | 7.5 | 1.4% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul... |
| CVE-2021-42641 | HIGH | 7.5 | 2.1% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul... |
| CVE-2021-42640 | CRITICAL | 9.1 | 2.1% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul... |
| CVE-2021-42639 | MEDIUM | 6.1 | 1.2% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulner... |
| CVE-2021-42637 | CRITICAL | 9.8 | 2.3% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server ... |
| CVE-2021-42633 | MEDIUM | 5.3 | 2.0% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to ... |
| CVE-2021-41018 | HIGH | 8.8 | 3.3% | Feb 2, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2021-39070 | CRITICAL | 9.8 | 1.8% | Feb 2, 2022 | IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabl... |
| CVE-2021-39066 | HIGH | 8.8 | 0.6% | Feb 2, 2022 | IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker th... |
| CVE-2021-39044 | HIGH | 8.8 | 0.4% | Feb 2, 2022 | IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2021-36193 | HIGH | 7.2 | 0.8% | Feb 2, 2022 | Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate... |
| CVE-2021-24043 | CRITICAL | 9.1 | 1.1% | Feb 2, 2022 | A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android ... |
| CVE-2021-43073 | HIGH | 8.8 | 1.4% | Feb 2, 2022 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2021-43062 | MEDIUM | 6.1 | 12.9% | Feb 2, 2022 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0... |
| CVE-2021-42753 | HIGH | 8.1 | 1.1% | Feb 2, 2022 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man... |
| CVE-2021-41016 | HIGH | 8.8 | 1.1% | Feb 2, 2022 | A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version ... |
| CVE-2021-36177 | MEDIUM | 4.3 | 0.3% | Feb 2, 2022 | An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x... |
| CVE-2021-42638 | HIGH | 8.1 | 5.7% | Feb 1, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code exe... |
| CVE-2021-46093 | CRITICAL | 9.8 | 1.2% | Feb 1, 2022 | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. |
| CVE-2021-38560 | MEDIUM | 6.1 | 2.9% | Feb 1, 2022 | Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in ... |
| CVE-2021-44746 | MEDIUM | 5.3 | 1.1% | Feb 1, 2022 | UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Man... |
| CVE-2021-44451 | MEDIUM | 6.5 | 7.9% | Feb 1, 2022 | Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated us... |
| CVE-2021-43510 | CRITICAL | 9.8 | 7.5% | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login... |
| CVE-2021-43509 | CRITICAL | 9.8 | 1.8% | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-se... |
| CVE-2021-46253 | MEDIUM | 5.4 | 0.6% | Feb 1, 2022 | A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now