2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43960 | MEDIUM | 4.8 | 0.6% | Jan 12, 2022 | Lorensbergs Connect2 3.13.7647.20190 is affected by an XSS vulnerability. Exploitation requires administrator privileges... |
| CVE-2021-42562 | HIGH | 8.1 | 1.2% | Jan 12, 2022 | An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users h... |
| CVE-2021-42561 | HIGH | 8.8 | 19.6% | Jan 12, 2022 | An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a py... |
| CVE-2021-42560 | HIGH | 8.8 | 2.1% | Jan 12, 2022 | An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a ... |
| CVE-2021-36417 | HIGH | 7.8 | 1.1% | Jan 12, 2022 | A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, whic... |
| CVE-2021-35500 | MEDIUM | 5.5 | 0.6% | Jan 12, 2022 | The Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, ... |
| CVE-2021-45445 | HIGH | 7.5 | 1.0% | Jan 12, 2022 | Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop. |
| CVE-2021-28377 | MEDIUM | 5.3 | 8.2% | Jan 12, 2022 | ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files. |
| CVE-2021-28376 | LOW | 2.7 | 1.1% | Jan 12, 2022 | ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files. |
| CVE-2021-45411 | CRITICAL | 9.8 | 3.9% | Jan 12, 2022 | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can... |
| CVE-2021-45388 | — | — | — | Jan 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-45608. Reason: This candidate is a reservation d... |
| CVE-2021-43436 | MEDIUM | 5.4 | 0.6% | Jan 12, 2022 | MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. ... |
| CVE-2021-38892 | — | — | — | Jan 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-44652 | HIGH | 7.8 | 2.6% | Jan 12, 2022 | Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the Ch... |
| CVE-2021-44651 | HIGH | 8.8 | 5.3% | Jan 12, 2022 | Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings... |
| CVE-2021-4080 | HIGH | 8.8 | 1.5% | Jan 12, 2022 | crater is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-44650 | HIGH | 7.2 | 4.8% | Jan 12, 2022 | Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings throu... |
| CVE-2021-44649 | MEDIUM | 5.4 | 0.6% | Jan 12, 2022 | Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type,... |
| CVE-2021-44648 | HIGH | 8.8 | 1.9% | Jan 12, 2022 | GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of... |
| CVE-2021-3852 | HIGH | 7.5 | 0.8% | Jan 12, 2022 | growi is vulnerable to Authorization Bypass Through User-Controlled Key |
| CVE-2021-46283 | MEDIUM | 5.5 | 0.3% | Jan 11, 2022 | nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denia... |
| CVE-2021-43999 | HIGH | 8.8 | 1.8% | Jan 11, 2022 | Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML supp... |
| CVE-2021-41767 | MEDIUM | 6.5 | 1.9% | Jan 11, 2022 | Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some ... |
| CVE-2021-43974 | MEDIUM | 5.3 | 1.4% | Jan 11, 2022 | An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, ... |
| CVE-2021-43973 | HIGH | 8.8 | 1.7% | Jan 11, 2022 | An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now