2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21873 | CRITICAL | 9.1 | 2.9% | Dec 22, 2021 | A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can mak... |
| CVE-2021-21872 | CRITICAL | 9.9 | 6.1% | Dec 22, 2021 | An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix Premi... |
| CVE-2021-45267 | MEDIUM | 5.5 | 0.6% | Dec 22, 2021 | An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a... |
| CVE-2021-45266 | HIGH | 7.5 | 1.1% | Dec 22, 2021 | A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a s... |
| CVE-2021-45263 | MEDIUM | 5.5 | 0.6% | Dec 22, 2021 | An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmen... |
| CVE-2021-45262 | MEDIUM | 5.5 | 0.6% | Dec 22, 2021 | An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault... |
| CVE-2021-45261 | MEDIUM | 5.5 | 0.7% | Dec 22, 2021 | An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service... |
| CVE-2021-45260 | MEDIUM | 5.5 | 0.6% | Dec 22, 2021 | A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentat... |
| CVE-2021-44659 | CRITICAL | 9.8 | 2.5% | Dec 22, 2021 | Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action... |
| CVE-2021-43804 | HIGH | 7.3 | 2.2% | Dec 22, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2021-43631 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment... |
| CVE-2021-43630 | HIGH | 8.8 | 2.0% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php.... |
| CVE-2021-43629 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php. |
| CVE-2021-43628 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php. |
| CVE-2021-43158 | MEDIUM | 4.3 | 0.5% | Dec 22, 2021 | In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to rem... |
| CVE-2021-43157 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php. |
| CVE-2021-43156 | MEDIUM | 6.5 | 0.5% | Dec 22, 2021 | In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete a... |
| CVE-2021-43155 | CRITICAL | 9.8 | 1.1% | Dec 22, 2021 | Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php. |
| CVE-2021-37706 | CRITICAL | 9.8 | 4.6% | Dec 22, 2021 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2021-4114 | — | — | — | Dec 22, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-4113 | — | — | — | Dec 22, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2021-45419 | HIGH | 8.8 | 0.6% | Dec 22, 2021 | Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <... |
| CVE-2021-45259 | MEDIUM | 5.5 | 0.7% | Dec 22, 2021 | An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segment... |
| CVE-2021-45258 | MEDIUM | 5.5 | 0.6% | Dec 22, 2021 | A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation... |
| CVE-2021-45257 | MEDIUM | 5.5 | 0.7% | Dec 22, 2021 | An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now