2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36426 | HIGH | 8.8 | 1.1% | Feb 3, 2023 | File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to inc... |
| CVE-2021-3809 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi... |
| CVE-2021-3808 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi... |
| CVE-2021-3439 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being re... |
| CVE-2021-22786 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on th... |
| CVE-2021-4315 | HIGH | 8.8 | 0.9% | Jan 28, 2023 | A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unkn... |
| CVE-2021-41231 | HIGH | 7.2 | 1.2% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to ... |
| CVE-2021-41144 | HIGH | 8.8 | 1.2% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the blo... |
| CVE-2021-41143 | HIGH | 7.2 | 1.3% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the cu... |
| CVE-2021-39217 | HIGH | 7.2 | 1.3% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to exec... |
| CVE-2021-41989 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions. |
| CVE-2021-41988 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions. |
| CVE-2021-28510 | HIGH | 7.5 | 1.0% | Jan 26, 2023 | For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invali... |
| CVE-2021-43449 | HIGH | 8.1 | 1.2% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor servic... |
| CVE-2021-43447 | HIGH | 7.5 | 1.3% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the docume... |
| CVE-2021-43444 | HIGH | 7.5 | 1.2% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be f... |
| CVE-2021-24881 | HIGH | 7.5 | 0.8% | Jan 23, 2023 | The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed... |
| CVE-2021-33641 | HIGH | 7.8 | 0.3% | Jan 20, 2023 | When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses... |
| CVE-2021-29368 | HIGH | 8.8 | 0.7% | Jan 20, 2023 | Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 all... |
| CVE-2021-37500 | HIGH | 8.1 | 1.2% | Jan 20, 2023 | Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics funct... |
| CVE-2021-27782 | HIGH | 7.5 | 0.3% | Jan 20, 2023 | HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked ou... |
| CVE-2021-37774 | HIGH | 8 | 0.9% | Jan 19, 2023 | An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code... |
| CVE-2021-33959 | HIGH | 7.5 | 15.0% | Jan 18, 2023 | Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service. |
| CVE-2021-36630 | HIGH | 7.5 | 2.4% | Jan 18, 2023 | DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote at... |
| CVE-2021-32837 | HIGH | 7.5 | 26.7% | Jan 17, 2023 | mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerab... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now