2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4177 | MEDIUM | 5.3 | 0.9% | Dec 28, 2021 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information |
| CVE-2021-20873 | HIGH | 8.1 | 0.8% | Dec 28, 2021 | Yappli is an application development platform which provides the function to access a requested URL using Custom URL Sch... |
| CVE-2021-45911 | HIGH | 7.8 | 0.9% | Dec 28, 2021 | An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attack... |
| CVE-2021-45910 | HIGH | 7.8 | 0.9% | Dec 28, 2021 | An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an at... |
| CVE-2021-45909 | HIGH | 7.8 | 0.9% | Dec 28, 2021 | An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. ... |
| CVE-2021-45908 | HIGH | 7.8 | 0.7% | Dec 28, 2021 | An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has ... |
| CVE-2021-45907 | HIGH | 7.8 | 0.7% | Dec 28, 2021 | An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has li... |
| CVE-2021-45906 | MEDIUM | 5.4 | 0.5% | Dec 27, 2021 | OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen. |
| CVE-2021-45905 | MEDIUM | 5.4 | 0.5% | Dec 27, 2021 | OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen. |
| CVE-2021-45904 | MEDIUM | 5.4 | 0.5% | Dec 27, 2021 | OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen. |
| CVE-2021-45896 | HIGH | 8.8 | 1.6% | Dec 27, 2021 | Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_we... |
| CVE-2021-45884 | HIGH | 7.5 | 2.7% | Dec 27, 2021 | In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fa... |
| CVE-2021-43858 | HIGH | 8.8 | 35.5% | Dec 27, 2021 | MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious... |
| CVE-2021-45895 | MEDIUM | 6.1 | 0.7% | Dec 27, 2021 | Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface. |
| CVE-2021-45890 | CRITICAL | 9.8 | 1.7% | Dec 27, 2021 | basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier. |
| CVE-2021-4161 | HIGH | 7.5 | 0.7% | Dec 27, 2021 | The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login ... |
| CVE-2021-43857 | HIGH | 8.8 | 55.6% | Dec 27, 2021 | Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code executi... |
| CVE-2021-43552 | MEDIUM | 5.5 | 0.2% | Dec 27, 2021 | The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from t... |
| CVE-2021-43550 | MEDIUM | 6.5 | 0.2% | Dec 27, 2021 | The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive... |
| CVE-2021-43548 | MEDIUM | 6.5 | 0.4% | Dec 27, 2021 | Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrect... |
| CVE-2021-35232 | MEDIUM | 6.1 | 0.3% | Dec 27, 2021 | Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with loca... |
| CVE-2021-33017 | HIGH | 8.8 | 0.5% | Dec 27, 2021 | The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the prod... |
| CVE-2021-32993 | HIGH | 8.8 | 0.3% | Dec 27, 2021 | IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographi... |
| CVE-2021-23244 | HIGH | 7.8 | 0.6% | Dec 27, 2021 | ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But s... |
| CVE-2021-21751 | HIGH | 8.1 | 0.8% | Dec 27, 2021 | ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and ba... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now