2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45472MEDIUM6.1In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that ...
CVE-2021-45471MEDIUM5.3In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
CVE-2021-45470HIGH7.5lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular ex...
CVE-2021-3622MEDIUM4.3A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive)...
CVE-2021-3621HIGH8.8A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach...
CVE-2021-4024MEDIUM6.5A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a...
CVE-2021-44543MEDIUM6.1An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Pr...
CVE-2021-44542HIGH7.5A memory leak vulnerability was found in Privoxy when handling errors.
CVE-2021-44541HIGH7.5A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory whe...
CVE-2021-44540HIGH7.5A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec ...
CVE-2021-44453CRITICAL9.8mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow...
CVE-2021-43989HIGH7.5mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously ...
CVE-2021-43987CRITICAL9.8An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not expose...
CVE-2021-43985CRITICAL9.8An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication...
CVE-2021-43984CRITICAL9.8mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to...
CVE-2021-43981CRITICAL9.8mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary o...
CVE-2021-3584HIGH7.2A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendm...
CVE-2021-35243HIGH7.5The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to exe...
CVE-2021-30767MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey ...
CVE-2021-27007CRITICAL9.8NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when succes...
CVE-2021-27006MEDIUM4.4StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may...
CVE-2021-23198CRITICAL9.8mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker ...
CVE-2021-22657CRITICAL9.8mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attac...
CVE-2021-20318HIGH7.2The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use th...
CVE-2021-45469HIGH7.8In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now