2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45452 | MEDIUM | 5.3 | 2.4% | Jan 5, 2022 | Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted ... |
| CVE-2021-45116 | HIGH | 7.5 | 1.8% | Jan 5, 2022 | An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Djan... |
| CVE-2021-45115 | HIGH | 7.5 | 2.4% | Jan 5, 2022 | An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityVal... |
| CVE-2021-41388 | HIGH | 7.8 | 0.2% | Jan 4, 2022 | Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation... |
| CVE-2021-22045 | HIGH | 7.8 | 4.7% | Jan 4, 2022 | VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and ... |
| CVE-2021-43852 | HIGH | 8.8 | 1.1% | Jan 4, 2022 | OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an atta... |
| CVE-2021-43850 | MEDIUM | 6.8 | 0.8% | Jan 4, 2022 | Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of... |
| CVE-2021-43832 | CRITICAL | 9.8 | 2.6% | Jan 4, 2022 | Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipel... |
| CVE-2021-43677 | MEDIUM | 6.1 | 0.6% | Jan 4, 2022 | Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability. |
| CVE-2021-41610 | — | — | — | Jan 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-27339. Reason: This candidate is a reservation d... |
| CVE-2021-41236 | MEDIUM | 4.8 | 0.7% | Jan 4, 2022 | OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS... |
| CVE-2021-41141 | HIGH | 7.5 | 1.4% | Jan 4, 2022 | PJSIP is a free and open source multimedia communication library written in the C language implementing standard based p... |
| CVE-2021-24042 | CRITICAL | 9.8 | 1.2% | Jan 4, 2022 | The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp ... |
| CVE-2021-39143 | HIGH | 7.1 | 0.3% | Jan 4, 2022 | Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in ... |
| CVE-2021-3845 | HIGH | 7.5 | 1.2% | Jan 4, 2022 | ws-scrcpy is vulnerable to External Control of File Name or Path |
| CVE-2021-45912 | HIGH | 7.8 | 0.3% | Jan 4, 2022 | An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attack... |
| CVE-2021-45389 | CRITICAL | 9.8 | 1.2% | Jan 4, 2022 | A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the au... |
| CVE-2021-41789 | MEDIUM | 6.5 | 0.6% | Jan 4, 2022 | In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of ... |
| CVE-2021-40148 | HIGH | 7.5 | 0.7% | Jan 4, 2022 | In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote inf... |
| CVE-2021-45980 | HIGH | 7.8 | 1.5% | Jan 4, 2022 | Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the ... |
| CVE-2021-45979 | HIGH | 7.8 | 1.5% | Jan 4, 2022 | Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL ... |
| CVE-2021-45978 | HIGH | 7.8 | 1.5% | Jan 4, 2022 | Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoU... |
| CVE-2021-45913 | HIGH | 7.2 | 1.0% | Jan 4, 2022 | A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS command... |
| CVE-2021-3842 | HIGH | 7.5 | 1.5% | Jan 4, 2022 | nltk is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-43711 | CRITICAL | 9.8 | 36.3% | Jan 4, 2022 | The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when re... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now