2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36347 | HIGH | 7.2 | 2.4% | Jan 25, 2022 | iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulner... |
| CVE-2021-36346 | MEDIUM | 5.3 | 4.2% | Jan 25, 2022 | Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker c... |
| CVE-2021-36296 | HIGH | 7.2 | 2.8% | Jan 25, 2022 | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A r... |
| CVE-2021-36295 | HIGH | 7.2 | 2.8% | Jan 25, 2022 | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A r... |
| CVE-2021-36294 | CRITICAL | 9.8 | 1.6% | Jan 25, 2022 | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthen... |
| CVE-2021-36289 | HIGH | 7.8 | 0.2% | Jan 25, 2022 | Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local... |
| CVE-2021-43799 | CRITICAL | 9.8 | 5.4% | Jan 25, 2022 | Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In version... |
| CVE-2021-4145 | MEDIUM | 6.5 | 0.4% | Jan 25, 2022 | A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` poin... |
| CVE-2021-4133 | HIGH | 8.8 | 1.3% | Jan 25, 2022 | A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user a... |
| CVE-2021-45729 | MEDIUM | 5.4 | 0.7% | Jan 25, 2022 | The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe... |
| CVE-2021-43298 | CRITICAL | 9.8 | 2.3% | Jan 25, 2022 | The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and ... |
| CVE-2021-41598 | HIGH | 8.8 | 1.2% | Jan 25, 2022 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be gran... |
| CVE-2021-40337 | MEDIUM | 5.4 | 0.4% | Jan 25, 2022 | Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulner... |
| CVE-2021-40167 | HIGH | 7.8 | 7.7% | Jan 25, 2022 | A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption ... |
| CVE-2021-40159 | HIGH | 7.8 | 2.3% | Jan 25, 2022 | An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with oth... |
| CVE-2021-40158 | HIGH | 7.8 | 2.9% | Jan 25, 2022 | A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond ... |
| CVE-2021-38129 | LOW | 3.3 | 0.2% | Jan 25, 2022 | Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and... |
| CVE-2021-39031 | HIGH | 8.8 | 2.3% | Jan 25, 2022 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to cond... |
| CVE-2021-46087 | MEDIUM | 5.4 | 0.5% | Jan 25, 2022 | In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not ... |
| CVE-2021-46086 | HIGH | 7.5 | 0.8% | Jan 25, 2022 | xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examina... |
| CVE-2021-46085 | MEDIUM | 6.5 | 0.7% | Jan 25, 2022 | OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators be... |
| CVE-2021-46084 | MEDIUM | 5.4 | 0.4% | Jan 25, 2022 | uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box. |
| CVE-2021-46083 | MEDIUM | 5.4 | 0.4% | Jan 25, 2022 | uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code. |
| CVE-2021-46034 | MEDIUM | 6.1 | 0.6% | Jan 25, 2022 | A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickn... |
| CVE-2021-43863 | HIGH | 7.5 | 1.9% | Jan 25, 2022 | The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Androi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now