2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37867 | MEDIUM | 4.3 | 0.7% | Jan 18, 2022 | Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, w... |
| CVE-2021-37866 | HIGH | 7.5 | 0.7% | Jan 18, 2022 | Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of ... |
| CVE-2021-37865 | MEDIUM | 5.7 | 0.9% | Jan 18, 2022 | Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while draft... |
| CVE-2021-37864 | MEDIUM | 6.5 | 0.6% | Jan 18, 2022 | Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth... |
| CVE-2021-29872 | MEDIUM | 5.4 | 0.8% | Jan 18, 2022 | IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injec... |
| CVE-2021-29632 | HIGH | 7.5 | 0.9% | Jan 18, 2022 | In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE... |
| CVE-2021-29215 | CRITICAL | 9.8 | 1.2% | Jan 18, 2022 | A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the T... |
| CVE-2021-4146 | MEDIUM | 4.3 | 0.8% | Jan 18, 2022 | Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6. |
| CVE-2021-44217 | MEDIUM | 6.1 | 1.6% | Jan 18, 2022 | In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of t... |
| CVE-2021-41551 | MEDIUM | 4.9 | 1.3% | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP fi... |
| CVE-2021-41550 | HIGH | 7.2 | 1.0% | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code. |
| CVE-2021-38697 | CRITICAL | 9.8 | 2.7% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files w... |
| CVE-2021-38696 | HIGH | 7.5 | 1.7% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature fi... |
| CVE-2021-38695 | MEDIUM | 5.4 | 0.8% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in... |
| CVE-2021-38785 | HIGH | 7.5 | 1.8% | Jan 18, 2022 | There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could u... |
| CVE-2021-38784 | HIGH | 7.5 | 1.8% | Jan 18, 2022 | There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that coul... |
| CVE-2021-38694 | HIGH | 7.5 | 1.5% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection. |
| CVE-2021-22566 | CRITICAL | 9.8 | 0.3% | Jan 18, 2022 | An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as exe... |
| CVE-2021-38783 | HIGH | 7.5 | 1.8% | Jan 18, 2022 | There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl ... |
| CVE-2021-33965 | HIGH | 8.8 | 2.9% | Jan 18, 2022 | China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by ... |
| CVE-2021-45394 | HIGH | 8.8 | 1.6% | Jan 18, 2022 | An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the ... |
| CVE-2021-33964 | HIGH | 8.8 | 2.9% | Jan 18, 2022 | China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives ... |
| CVE-2021-44757 | CRITICAL | 9.1 | 24.2% | Jan 18, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypas... |
| CVE-2021-42357 | MEDIUM | 6.1 | 2.6% | Jan 17, 2022 | When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to impr... |
| CVE-2021-38965 | HIGH | 8.8 | 1.8% | Jan 17, 2022 | IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary com... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now