2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46385 | HIGH | 7.5 | 1.5% | Jan 26, 2022 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information ... |
| CVE-2021-46114 | HIGH | 8.8 | 1.7% | Jan 26, 2022 | jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides ... |
| CVE-2021-46561 | HIGH | 7.2 | 0.8% | Jan 26, 2022 | controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb53830... |
| CVE-2021-29846 | LOW | 2.7 | 0.6% | Jan 26, 2022 | IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient... |
| CVE-2021-29845 | HIGH | 8.8 | 0.8% | Jan 26, 2022 | IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper inp... |
| CVE-2021-29838 | MEDIUM | 5.9 | 1.3% | Jan 26, 2022 | IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2021-46386 | CRITICAL | 9.8 | 3.1% | Jan 26, 2022 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafte... |
| CVE-2021-46383 | HIGH | 7.5 | 1.6% | Jan 26, 2022 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information ... |
| CVE-2021-46118 | HIGH | 7.2 | 2.8% | Jan 26, 2022 | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The a... |
| CVE-2021-46116 | HIGH | 7.2 | 2.5% | Jan 26, 2022 | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin pan... |
| CVE-2021-46115 | HIGH | 7.2 | 1.3% | Jan 26, 2022 | jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a f... |
| CVE-2021-46117 | HIGH | 7.2 | 3.3% | Jan 26, 2022 | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel... |
| CVE-2021-44692 | MEDIUM | 5.3 | 1.1% | Jan 26, 2022 | BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new u... |
| CVE-2021-43334 | MEDIUM | 5.4 | 0.6% | Jan 26, 2022 | BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field. |
| CVE-2021-45975 | HIGH | 7.8 | 0.6% | Jan 26, 2022 | In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs coul... |
| CVE-2021-22600 | HIGH | 7 | 5.9% | Jan 26, 2022 | A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscal... |
| CVE-2021-22570 | MEDIUM | 5.5 | 2.7% | Jan 26, 2022 | Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unche... |
| CVE-2021-44123 | HIGH | 8.8 | 2.4% | Jan 26, 2022 | SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft... |
| CVE-2021-44122 | HIGH | 8.8 | 0.5% | Jan 26, 2022 | SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/publi... |
| CVE-2021-44120 | MEDIUM | 5.4 | 0.6% | Jan 26, 2022 | SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the functio... |
| CVE-2021-44118 | MEDIUM | 5.4 | 0.8% | Jan 26, 2022 | SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must brows... |
| CVE-2021-41766 | HIGH | 8.1 | 2.0% | Jan 26, 2022 | Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX i... |
| CVE-2021-46560 | CRITICAL | 9.8 | 3.6% | Jan 26, 2022 | The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage. |
| CVE-2021-46559 | HIGH | 7.5 | 0.4% | Jan 26, 2022 | The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection me... |
| CVE-2021-36348 | HIGH | 8.1 | 1.1% | Jan 25, 2022 | iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now