2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45472 | MEDIUM | 6.1 | 1.0% | Dec 24, 2021 | In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that ... |
| CVE-2021-45471 | MEDIUM | 5.3 | 1.2% | Dec 24, 2021 | In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. |
| CVE-2021-45470 | HIGH | 7.5 | 1.9% | Dec 23, 2021 | lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular ex... |
| CVE-2021-3622 | MEDIUM | 4.3 | 4.8% | Dec 23, 2021 | A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive)... |
| CVE-2021-3621 | HIGH | 8.8 | 2.5% | Dec 23, 2021 | A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach... |
| CVE-2021-4024 | MEDIUM | 6.5 | 1.1% | Dec 23, 2021 | A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a... |
| CVE-2021-44543 | MEDIUM | 6.1 | 0.8% | Dec 23, 2021 | An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Pr... |
| CVE-2021-44542 | HIGH | 7.5 | 1.2% | Dec 23, 2021 | A memory leak vulnerability was found in Privoxy when handling errors. |
| CVE-2021-44541 | HIGH | 7.5 | 1.4% | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory whe... |
| CVE-2021-44540 | HIGH | 7.5 | 1.3% | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec ... |
| CVE-2021-44453 | CRITICAL | 9.8 | 1.4% | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow... |
| CVE-2021-43989 | HIGH | 7.5 | 0.7% | Dec 23, 2021 | mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously ... |
| CVE-2021-43987 | CRITICAL | 9.8 | 1.2% | Dec 23, 2021 | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not expose... |
| CVE-2021-43985 | CRITICAL | 9.8 | 1.5% | Dec 23, 2021 | An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication... |
| CVE-2021-43984 | CRITICAL | 9.8 | 1.2% | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to... |
| CVE-2021-43981 | CRITICAL | 9.8 | 1.2% | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary o... |
| CVE-2021-3584 | HIGH | 7.2 | 3.9% | Dec 23, 2021 | A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendm... |
| CVE-2021-35243 | HIGH | 7.5 | 0.9% | Dec 23, 2021 | The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to exe... |
| CVE-2021-30767 | MEDIUM | 5.5 | 0.3% | Dec 23, 2021 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey ... |
| CVE-2021-27007 | CRITICAL | 9.8 | 1.1% | Dec 23, 2021 | NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when succes... |
| CVE-2021-27006 | MEDIUM | 4.4 | 0.3% | Dec 23, 2021 | StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may... |
| CVE-2021-23198 | CRITICAL | 9.8 | 1.2% | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker ... |
| CVE-2021-22657 | CRITICAL | 9.8 | 1.2% | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attac... |
| CVE-2021-20318 | HIGH | 7.2 | 1.7% | Dec 23, 2021 | The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use th... |
| CVE-2021-45469 | HIGH | 7.8 | 0.5% | Dec 23, 2021 | In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now