2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46322 | MEDIUM | 5.5 | 0.7% | Jan 20, 2022 | Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack... |
| CVE-2021-46061 | CRITICAL | 9.8 | 1.6% | Jan 20, 2022 | An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via... |
| CVE-2021-29785 | MEDIUM | 5.9 | 1.3% | Jan 20, 2022 | IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to pro... |
| CVE-2021-44245 | CRITICAL | 9.8 | 1.4% | Jan 20, 2022 | An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) userna... |
| CVE-2021-44244 | CRITICAL | 9.8 | 1.3% | Jan 20, 2022 | An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username para... |
| CVE-2021-44092 | CRITICAL | 9.8 | 1.3% | Jan 20, 2022 | An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the adminis... |
| CVE-2021-44090 | CRITICAL | 9.8 | 1.1% | Jan 20, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. |
| CVE-2021-45417 | HIGH | 7.8 | 0.5% | Jan 20, 2022 | AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attribut... |
| CVE-2021-44091 | MEDIUM | 5.4 | 0.6% | Jan 20, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in reg... |
| CVE-2021-44829 | MEDIUM | 6.1 | 1.6% | Jan 20, 2022 | Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter. |
| CVE-2021-44737 | HIGH | 8.8 | 1.4% | Jan 20, 2022 | PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal ... |
| CVE-2021-44736 | CRITICAL | 9.8 | 2.4% | Jan 20, 2022 | The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” fea... |
| CVE-2021-44735 | CRITICAL | 9.8 | 7.7% | Jan 20, 2022 | Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07. |
| CVE-2021-44734 | CRITICAL | 9.8 | 6.4% | Jan 20, 2022 | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to ... |
| CVE-2021-44738 | CRITICAL | 9.8 | 3.3% | Jan 20, 2022 | Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter. |
| CVE-2021-32039 | MEDIUM | 5.5 | 0.3% | Jan 20, 2022 | Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS ... |
| CVE-2021-34600 | MEDIUM | 5.5 | 0.4% | Jan 20, 2022 | Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used... |
| CVE-2021-45230 | MEDIUM | 6.5 | 1.7% | Jan 20, 2022 | In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on D... |
| CVE-2021-3866 | MEDIUM | 5.4 | 0.9% | Jan 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6... |
| CVE-2021-43269 | HIGH | 8.8 | 1.3% | Jan 20, 2022 | In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a maliciou... |
| CVE-2021-46028 | MEDIUM | 4.3 | 0.4% | Jan 20, 2022 | In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF loa... |
| CVE-2021-46026 | MEDIUM | 5.4 | 0.4% | Jan 20, 2022 | mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag... |
| CVE-2021-4143 | MEDIUM | 6.1 | 0.9% | Jan 19, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0. |
| CVE-2021-46027 | MEDIUM | 6.5 | 0.4% | Jan 19, 2022 | mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSR... |
| CVE-2021-46025 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now