2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3902 | CRITICAL | 9.8 | 0.9% | Nov 15, 2024 | An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Re... |
| CVE-2021-3838 | CRITICAL | 9.8 | 1.4% | Nov 15, 2024 | DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passi... |
| CVE-2021-35473 | CRITICAL | 9.1 | 0.4% | Nov 10, 2024 | An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e... |
| CVE-2021-4449 | CRITICAL | 9.8 | 5.3% | Oct 16, 2024 | The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '... |
| CVE-2021-4448 | CRITICAL | 9.8 | 1.3% | Oct 16, 2024 | The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including... |
| CVE-2021-4443 | CRITICAL | 9.8 | 0.7% | Oct 16, 2024 | The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, ... |
| CVE-2021-27915 | CRITICAL | 9 | 0.6% | Sep 17, 2024 | Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic... |
| CVE-2021-38132 | CRITICAL | 9.8 | 0.4% | Sep 12, 2024 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al... |
| CVE-2021-22533 | CRITICAL | 9.1 | 0.4% | Sep 12, 2024 | Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ ... |
| CVE-2021-22530 | CRITICAL | 9.9 | 0.2% | Aug 28, 2024 | A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack ... |
| CVE-2021-47548 | CRITICAL | 9.8 | 1.4% | May 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: ethernet: hisilicon: hns: hns_dsaf_misc: fix a poss... |
| CVE-2021-47478 | CRITICAL | 9.1 | 0.2% | May 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs ... |
| CVE-2021-47378 | CRITICAL | 9.8 | 1.2% | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid... |
| CVE-2021-47348 | CRITICAL | 9.1 | 1.0% | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruptio... |
| CVE-2021-47232 | CRITICAL | 9.8 | 0.2% | May 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix Use-after-Free, hold skb ref while ... |
| CVE-2021-27312 | CRITICAL | 9.4 | 1.0% | Apr 3, 2024 | Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code a... |
| CVE-2021-47137 | CRITICAL | 9.8 | 0.2% | Mar 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a... |
| CVE-2021-47157 | CRITICAL | 9.8 | 0.4% | Mar 18, 2024 | The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling. |
| CVE-2021-47155 | CRITICAL | 9.1 | 0.5% | Mar 18, 2024 | The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, wh... |
| CVE-2021-4436 | CRITICAL | 9.8 | 6.7% | Feb 5, 2024 | The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in... |
| CVE-2021-21575 | CRITICAL | 9.8 | 0.5% | Feb 2, 2024 | Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability. |
| CVE-2021-42147 | CRITICAL | 9.1 | 0.8% | Jan 24, 2024 | Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 a... |
| CVE-2021-42144 | CRITICAL | 9.8 | 0.7% | Jan 24, 2024 | Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive in... |
| CVE-2021-42143 | CRITICAL | 9.1 | 0.8% | Jan 24, 2024 | An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the han... |
| CVE-2021-42142 | CRITICAL | 9.8 | 1.0% | Jan 23, 2024 | An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now