2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25991 | HIGH | 7.3 | 0.8% | Dec 29, 2021 | In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins ... |
| CVE-2021-25990 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading... |
| CVE-2021-25989 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be e... |
| CVE-2021-25988 | MEDIUM | 5.4 | 0.6% | Dec 29, 2021 | In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can b... |
| CVE-2021-44161 | HIGH | 8.8 | 0.5% | Dec 29, 2021 | Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input... |
| CVE-2021-44160 | HIGH | 7.3 | 1.1% | Dec 29, 2021 | Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire anoth... |
| CVE-2021-44832 | MEDIUM | 6.6 | 97.9% | Dec 28, 2021 | Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r... |
| CVE-2021-44771 | — | — | — | Dec 28, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-43556 | HIGH | 7.8 | 2.1% | Dec 28, 2021 | FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing projec... |
| CVE-2021-43554 | HIGH | 7.8 | 1.9% | Dec 28, 2021 | FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files... |
| CVE-2021-42583 | HIGH | 7.5 | 0.7% | Dec 28, 2021 | A Broken or Risky Cryptographic Algorithm exists in Max Mazurov Maddy before 0.5.2, which is an unnecessary risk that ma... |
| CVE-2021-3095 | — | — | — | Dec 28, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43551. Reason: This candidate is a reservation d... |
| CVE-2021-3090 | — | — | — | Dec 28, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43553. Reason: This candidate is a reservation d... |
| CVE-2021-23151 | — | — | — | Dec 28, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-45814 | CRITICAL | 9.8 | 6.3% | Dec 28, 2021 | Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel ... |
| CVE-2021-45813 | MEDIUM | 6.1 | 0.6% | Dec 28, 2021 | SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's ses... |
| CVE-2021-45812 | MEDIUM | 6.1 | 0.8% | Dec 28, 2021 | NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can ste... |
| CVE-2021-45903 | MEDIUM | 6.1 | 1.1% | Dec 28, 2021 | A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x bef... |
| CVE-2021-45425 | MEDIUM | 6.1 | 3.4% | Dec 28, 2021 | Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip... |
| CVE-2021-37401 | CRITICAL | 9.8 | 1.3% | Dec 28, 2021 | An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a... |
| CVE-2021-37400 | CRITICAL | 9.8 | 1.3% | Dec 28, 2021 | An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PL... |
| CVE-2021-40579 | MEDIUM | 6.5 | 0.8% | Dec 28, 2021 | https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected b... |
| CVE-2021-35032 | HIGH | 7.8 | 0.2% | Dec 28, 2021 | A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local u... |
| CVE-2021-35031 | HIGH | 8 | 0.5% | Dec 28, 2021 | A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware... |
| CVE-2021-4179 | MEDIUM | 5.4 | 0.5% | Dec 28, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now