2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43764 | MEDIUM | 5.4 | 1.5% | Jan 13, 2022 | AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS... |
| CVE-2021-43762 | MEDIUM | 6.5 | 1.6% | Jan 13, 2022 | AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability ... |
| CVE-2021-43761 | MEDIUM | 5.4 | 1.1% | Jan 13, 2022 | AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are a... |
| CVE-2021-40722 | CRITICAL | 9.8 | 3.3% | Jan 13, 2022 | AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) i... |
| CVE-2021-33046 | CRITICAL | 9.8 | 1.3% | Jan 13, 2022 | Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerab... |
| CVE-2021-23227 | HIGH | 8.8 | 0.4% | Jan 13, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions. |
| CVE-2021-45807 | CRITICAL | 9.8 | 2.6% | Jan 13, 2022 | jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. |
| CVE-2021-45422 | MEDIUM | 6.1 | 3.3% | Jan 13, 2022 | Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_proce... |
| CVE-2021-40576 | MEDIUM | 5.5 | 0.9% | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in h... |
| CVE-2021-40575 | MEDIUM | 5.5 | 0.9% | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in refram... |
| CVE-2021-40574 | HIGH | 7.8 | 1.3% | Jan 13, 2022 | The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line funct... |
| CVE-2021-40573 | MEDIUM | 5.5 | 0.7% | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows atta... |
| CVE-2021-40572 | MEDIUM | 5.5 | 0.9% | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows att... |
| CVE-2021-40813 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote... |
| CVE-2021-40571 | HIGH | 7.8 | 1.2% | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which... |
| CVE-2021-40570 | HIGH | 7.8 | 1.2% | Jan 13, 2022 | The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which a... |
| CVE-2021-40569 | MEDIUM | 5.5 | 0.9% | Jan 13, 2022 | The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta.... |
| CVE-2021-40568 | HIGH | 7.8 | 1.3% | Jan 13, 2022 | A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in... |
| CVE-2021-40567 | MEDIUM | 5.5 | 0.9% | Jan 13, 2022 | Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c ... |
| CVE-2021-39056 | MEDIUM | 6.5 | 1.3% | Jan 13, 2022 | The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to ... |
| CVE-2021-40327 | MEDIUM | 5.9 | 1.2% | Jan 13, 2022 | Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key ... |
| CVE-2021-23824 | MEDIUM | 6.1 | 0.9% | Jan 13, 2022 | This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipu... |
| CVE-2021-45806 | HIGH | 8.8 | 1.7% | Jan 13, 2022 | jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious ... |
| CVE-2021-23514 | HIGH | 7.5 | 1.6% | Jan 13, 2022 | This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the ser... |
| CVE-2021-30353 | HIGH | 7.5 | 0.6% | Jan 13, 2022 | Improper validation of function pointer type with actual function signature can lead to assertion in Snapdragon Auto, Sn... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now