2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4172 | MEDIUM | 5.4 | 0.6% | Jan 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. |
| CVE-2021-39480 | HIGH | 7.5 | 1.1% | Jan 21, 2022 | Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS). |
| CVE-2021-46313 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned... |
| CVE-2021-46311 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vr... |
| CVE-2021-46244 | MEDIUM | 6.5 | 1.0% | Jan 21, 2022 | A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This ... |
| CVE-2021-46243 | MEDIUM | 6.5 | 1.0% | Jan 21, 2022 | An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at ... |
| CVE-2021-46242 | HIGH | 8.8 | 1.2% | Jan 21, 2022 | HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry. |
| CVE-2021-46240 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager... |
| CVE-2021-46239 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at ... |
| CVE-2021-46238 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegrap... |
| CVE-2021-46237 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegrap... |
| CVE-2021-46236 | MEDIUM | 5.5 | 0.7% | Jan 21, 2022 | A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_vrml_field_pointer_del () at scene... |
| CVE-2021-46234 | MEDIUM | 5.5 | 0.7% | Jan 21, 2022 | A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base... |
| CVE-2021-36339 | HIGH | 7.8 | 0.2% | Jan 21, 2022 | The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentiall... |
| CVE-2021-36338 | HIGH | 8 | 0.4% | Jan 21, 2022 | Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious us... |
| CVE-2021-40595 | CRITICAL | 9.8 | 1.4% | Jan 21, 2022 | SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execut... |
| CVE-2021-23664 | HIGH | 7.5 | 1.4% | Jan 21, 2022 | The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing ... |
| CVE-2021-23631 | HIGH | 7.5 | 2.0% | Jan 21, 2022 | This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of packa... |
| CVE-2021-23518 | CRITICAL | 9.8 | 1.9% | Jan 21, 2022 | The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set a... |
| CVE-2021-23460 | HIGH | 7.5 | 2.3% | Jan 21, 2022 | The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of... |
| CVE-2021-4032 | MEDIUM | 4.4 | 0.4% | Jan 21, 2022 | A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allo... |
| CVE-2021-4001 | MEDIUM | 4.1 | 0.2% | Jan 21, 2022 | A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a m... |
| CVE-2021-44593 | HIGH | 8.1 | 4.2% | Jan 21, 2022 | Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL inje... |
| CVE-2021-44464 | HIGH | 8.8 | 0.6% | Jan 21, 2022 | Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across al... |
| CVE-2021-43355 | CRITICAL | 9.8 | 1.0% | Jan 21, 2022 | Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the cl... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now