2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37214 | HIGH | 8.8 | 1.1% | Aug 9, 2021 | The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authen... |
| CVE-2021-24521 | HIGH | 7.2 | 1.6% | Aug 9, 2021 | The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from... |
| CVE-2021-24520 | HIGH | 8.8 | 1.6% | Aug 9, 2021 | The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, ... |
| CVE-2021-24501 | HIGH | 8.1 | 1.3% | Aug 9, 2021 | The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user wa... |
| CVE-2021-24500 | HIGH | 8.1 | 0.6% | Aug 9, 2021 | Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing... |
| CVE-2021-38207 | HIGH | 7.5 | 3.4% | Aug 8, 2021 | drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial... |
| CVE-2021-38202 | HIGH | 7.5 | 3.2% | Aug 8, 2021 | fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-boun... |
| CVE-2021-38201 | HIGH | 7.5 | 3.4% | Aug 8, 2021 | net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_ba... |
| CVE-2021-38192 | HIGH | 7.5 | 1.1% | Aug 8, 2021 | An issue was discovered in the prost-types crate before 0.8.0 for Rust. An overflow can occur during conversion from Tim... |
| CVE-2021-38185 | HIGH | 7.8 | 4.2% | Aug 8, 2021 | GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_f... |
| CVE-2021-38169 | HIGH | 8.8 | 1.5% | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py. |
| CVE-2021-38168 | HIGH | 8.8 | 0.9% | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers. |
| CVE-2021-38166 | HIGH | 7.8 | 0.3% | Aug 7, 2021 | In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when ma... |
| CVE-2021-29923 | HIGH | 7.5 | 3.7% | Aug 7, 2021 | Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in ... |
| CVE-2021-38160 | HIGH | 7.8 | 0.4% | Aug 7, 2021 | In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untru... |
| CVE-2021-38155 | HIGH | 7.5 | 2.5% | Aug 6, 2021 | OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allow... |
| CVE-2021-35312 | HIGH | 7.8 | 1.1% | Aug 6, 2021 | A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv... |
| CVE-2021-36795 | HIGH | 7.8 | 0.2% | Aug 6, 2021 | A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.... |
| CVE-2021-20594 | HIGH | 7.5 | 2.4% | Aug 6, 2021 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safet... |
| CVE-2021-36455 | HIGH | 8.8 | 1.1% | Aug 6, 2021 | SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comment... |
| CVE-2021-38137 | HIGH | 8.1 | 0.7% | Aug 6, 2021 | Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, a... |
| CVE-2021-37553 | HIGH | 7.5 | 1.5% | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used. |
| CVE-2021-37550 | HIGH | 7.5 | 1.1% | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used. |
| CVE-2021-37548 | HIGH | 7.5 | 0.6% | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS. |
| CVE-2021-37545 | HIGH | 7.5 | 0.9% | Aug 6, 2021 | In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now