2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26042 | — | — | — | Jan 19, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2021-26041 | — | — | — | Jan 19, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2021-44839 | MEDIUM | 6.5 | 0.6% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the accoun... |
| CVE-2021-44838 | MEDIUM | 4.3 | 0.9% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating ... |
| CVE-2021-44836 | MEDIUM | 4.3 | 0.6% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it i... |
| CVE-2021-44840 | LOW | 2.7 | 0.6% | Jan 18, 2022 | An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk la... |
| CVE-2021-46013 | CRITICAL | 9.8 | 3.5% | Jan 18, 2022 | An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can ... |
| CVE-2021-46012 | — | — | — | Jan 18, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA |
| CVE-2021-46005 | MEDIUM | 5.4 | 2.9% | Jan 18, 2022 | Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter... |
| CVE-2021-34406 | MEDIUM | 4.7 | 0.2% | Jan 18, 2022 | NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointe... |
| CVE-2021-34405 | MEDIUM | 5.5 | 0.2% | Jan 18, 2022 | NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value c... |
| CVE-2021-34404 | HIGH | 7.6 | 0.2% | Jan 18, 2022 | Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA whe... |
| CVE-2021-34403 | HIGH | 7.8 | 0.3% | Jan 18, 2022 | NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit... |
| CVE-2021-34402 | MEDIUM | 6.7 | 0.3% | Jan 18, 2022 | NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to ... |
| CVE-2021-34401 | HIGH | 7.8 | 0.3% | Jan 18, 2022 | NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where imprope... |
| CVE-2021-4083 | HIGH | 7 | 0.3% | Jan 18, 2022 | A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in... |
| CVE-2021-4074 | MEDIUM | 5.4 | 0.6% | Jan 18, 2022 | The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter fou... |
| CVE-2021-43353 | HIGH | 8.8 | 0.6% | Jan 18, 2022 | The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the... |
| CVE-2021-41809 | MEDIUM | 4.3 | 0.6% | Jan 18, 2022 | SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making qu... |
| CVE-2021-41808 | LOW | 2.3 | 0.2% | Jan 18, 2022 | In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log ... |
| CVE-2021-41807 | CRITICAL | 9.8 | 1.1% | Jan 18, 2022 | Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of u... |
| CVE-2021-39946 | MEDIUM | 5.4 | 1.0% | Jan 18, 2022 | Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowe... |
| CVE-2021-39942 | MEDIUM | 6.5 | 1.4% | Jan 18, 2022 | A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions ... |
| CVE-2021-39927 | MEDIUM | 4.3 | 0.6% | Jan 18, 2022 | Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and ... |
| CVE-2021-39892 | MEDIUM | 4.3 | 1.2% | Jan 18, 2022 | In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now