2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44777 | MEDIUM | 4.3 | 0.4% | Jan 19, 2022 | Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email ... |
| CVE-2021-3816 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix fi... |
| CVE-2021-26247 | MEDIUM | 6.1 | 7.1% | Jan 19, 2022 | As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" t... |
| CVE-2021-23843 | HIGH | 7.8 | 0.2% | Jan 19, 2022 | The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices.... |
| CVE-2021-23842 | HIGH | 7.1 | 0.1% | Jan 19, 2022 | Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An a... |
| CVE-2021-23225 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "... |
| CVE-2021-38789 | HIGH | 7.5 | 1.3% | Jan 19, 2022 | Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the c... |
| CVE-2021-46204 | CRITICAL | 9.8 | 1.1% | Jan 19, 2022 | Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulne... |
| CVE-2021-46203 | MEDIUM | 6.5 | 1.1% | Jan 19, 2022 | Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. |
| CVE-2021-44299 | MEDIUM | 5.4 | 0.4% | Jan 19, 2022 | A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows au... |
| CVE-2021-42810 | HIGH | 7.8 | 0.3% | Jan 19, 2022 | A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a priv... |
| CVE-2021-33913 | CRITICAL | 9.8 | 9.6% | Jan 19, 2022 | libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via ... |
| CVE-2021-33912 | CRITICAL | 9.8 | 9.6% | Jan 19, 2022 | libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary ... |
| CVE-2021-38788 | HIGH | 7.5 | 1.7% | Jan 19, 2022 | The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious app... |
| CVE-2021-46030 | MEDIUM | 5.4 | 0.5% | Jan 19, 2022 | There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into t... |
| CVE-2021-44837 | MEDIUM | 4.3 | 0.8% | Jan 19, 2022 | An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an ad... |
| CVE-2021-46104 | HIGH | 7.5 | 4.2% | Jan 19, 2022 | An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi... |
| CVE-2021-45808 | HIGH | 8.8 | 1.6% | Jan 19, 2022 | jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the s... |
| CVE-2021-38787 | HIGH | 7.5 | 1.9% | Jan 19, 2022 | There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the io... |
| CVE-2021-38786 | HIGH | 7.5 | 1.8% | Jan 19, 2022 | There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could ca... |
| CVE-2021-35687 | MEDIUM | 5.3 | 1.1% | Jan 19, 2022 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2021-35686 | MEDIUM | 4.3 | 0.7% | Jan 19, 2022 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2021-35683 | CRITICAL | 9.9 | 1.2% | Jan 19, 2022 | Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supp... |
| CVE-2021-35587 | CRITICAL | 9.8 | 96.3% | Jan 19, 2022 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver... |
| CVE-2021-31854 | HIGH | 7.8 | 1.0% | Jan 19, 2022 | A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now