2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32467 | HIGH | 7.5 | 1.0% | Dec 26, 2021 | MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected... |
| CVE-2021-4166 | HIGH | 7.1 | 1.6% | Dec 25, 2021 | vim is vulnerable to Out-of-bounds Read |
| CVE-2021-4162 | MEDIUM | 4.3 | 0.4% | Dec 25, 2021 | archivy is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-45489 | HIGH | 7.5 | 1.0% | Dec 25, 2021 | In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG. |
| CVE-2021-45488 | HIGH | 7.5 | 1.0% | Dec 25, 2021 | In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm. |
| CVE-2021-45487 | HIGH | 7.5 | 1.0% | Dec 25, 2021 | In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures. |
| CVE-2021-45486 | LOW | 3.5 | 0.4% | Dec 25, 2021 | In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash ... |
| CVE-2021-45485 | HIGH | 7.5 | 3.6% | Dec 25, 2021 | In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of ... |
| CVE-2021-45484 | HIGH | 7.5 | 1.0% | Dec 25, 2021 | In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG. |
| CVE-2021-45483 | MEDIUM | 6.5 | 1.4% | Dec 25, 2021 | In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-3... |
| CVE-2021-45482 | MEDIUM | 6.5 | 1.4% | Dec 25, 2021 | In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability t... |
| CVE-2021-45481 | MEDIUM | 6.5 | 1.4% | Dec 25, 2021 | In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create... |
| CVE-2021-45480 | MEDIUM | 5.5 | 0.4% | Dec 24, 2021 | An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function i... |
| CVE-2021-3977 | MEDIUM | 5.4 | 0.6% | Dec 24, 2021 | invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-23574 | CRITICAL | 9.8 | 2.1% | Dec 24, 2021 | All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is ... |
| CVE-2021-23490 | HIGH | 7.5 | 1.8% | Dec 24, 2021 | The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkH... |
| CVE-2021-4072 | MEDIUM | 5.4 | 0.7% | Dec 24, 2021 | elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-23772 | HIGH | 8.8 | 1.8% | Dec 24, 2021 | This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The u... |
| CVE-2021-20876 | MEDIUM | 6.8 | 1.0% | Dec 24, 2021 | Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlie... |
| CVE-2021-20875 | MEDIUM | 6.1 | 0.8% | Dec 24, 2021 | Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier... |
| CVE-2021-20874 | HIGH | 7.5 | 1.3% | Dec 24, 2021 | Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, G... |
| CVE-2021-20827 | HIGH | 7.5 | 0.6% | Dec 24, 2021 | Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earli... |
| CVE-2021-20826 | HIGH | 7.6 | 0.4% | Dec 24, 2021 | Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and ... |
| CVE-2021-45474 | MEDIUM | 6.1 | 1.0% | Dec 24, 2021 | In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl pa... |
| CVE-2021-45473 | MEDIUM | 6.1 | 1.2% | Dec 24, 2021 | In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now