2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23568 | CRITICAL | 9.8 | 1.5% | Jan 10, 2022 | The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive m... |
| CVE-2021-23543 | CRITICAL | 9.8 | 1.8% | Jan 10, 2022 | All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector. |
| CVE-2021-23173 | MEDIUM | 4.3 | 0.5% | Jan 10, 2022 | The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthor... |
| CVE-2021-22569 | MEDIUM | 5.5 | 1.7% | Jan 10, 2022 | An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that woul... |
| CVE-2021-22060 | MEDIUM | 4.3 | 0.9% | Jan 10, 2022 | In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user t... |
| CVE-2021-20048 | HIGH | 8.8 | 1.9% | Jan 10, 2022 | A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to ca... |
| CVE-2021-20046 | HIGH | 8.8 | 1.9% | Jan 10, 2022 | A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker ... |
| CVE-2021-38674 | MEDIUM | 6.1 | 0.6% | Jan 7, 2022 | A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this ... |
| CVE-2021-25743 | LOW | 3 | 0.8% | Jan 7, 2022 | kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This i... |
| CVE-2021-46044 | MEDIUM | 5.5 | 0.6% | Jan 6, 2022 | A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1via ShiftMetaOffset.isra, which causes a Denial of Service (conte... |
| CVE-2021-46043 | MEDIUM | 5.5 | 0.6% | Jan 6, 2022 | A Pointer Dereference Vulnerability exits in GPAC 1.0.1 in the gf_list_count function, which causes a Denial of Service. |
| CVE-2021-42841 | MEDIUM | 6.1 | 0.9% | Jan 6, 2022 | Insta HMS before 12.4.10 is vulnerable to XSS because of improper validation of user-supplied input by multiple scripts.... |
| CVE-2021-46042 | MEDIUM | 5.5 | 0.6% | Jan 6, 2022 | A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko function, which causes a Denial of Service. |
| CVE-2021-46041 | MEDIUM | 5.5 | 0.6% | Jan 6, 2022 | A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service. |
| CVE-2021-46040 | MEDIUM | 5.5 | 0.6% | Jan 6, 2022 | A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_moov_meta_offsets function, which causes ... |
| CVE-2021-46039 | MEDIUM | 5.5 | 0.6% | Jan 6, 2022 | A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial... |
| CVE-2021-4194 | MEDIUM | 6.5 | 0.7% | Jan 6, 2022 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-43045 | HIGH | 7.5 | 3.0% | Jan 6, 2022 | A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a... |
| CVE-2021-28715 | MEDIUM | 6.5 | 0.3% | Jan 6, 2022 | Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multi... |
| CVE-2021-28714 | MEDIUM | 6.5 | 0.3% | Jan 6, 2022 | Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multi... |
| CVE-2021-46079 | HIGH | 7.2 | 3.3% | Jan 6, 2022 | An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac... |
| CVE-2021-46078 | MEDIUM | 4.8 | 1.3% | Jan 6, 2022 | An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac... |
| CVE-2021-46075 | HIGH | 7.2 | 2.6% | Jan 6, 2022 | A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users... |
| CVE-2021-46074 | MEDIUM | 4.8 | 1.1% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the... |
| CVE-2021-46073 | MEDIUM | 4.8 | 2.8% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now