2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43439 | CRITICAL | 9.8 | 3.4% | Dec 20, 2021 | RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely |
| CVE-2021-43438 | MEDIUM | 5.4 | 0.7% | Dec 20, 2021 | Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field |
| CVE-2021-43437 | HIGH | 8.8 | 1.2% | Dec 20, 2021 | In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the we... |
| CVE-2021-44525 | CRITICAL | 9.8 | 3.4% | Dec 20, 2021 | Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a fi... |
| CVE-2021-44676 | CRITICAL | 9.8 | 4.4% | Dec 20, 2021 | Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control detail... |
| CVE-2021-44675 | CRITICAL | 9.8 | 6.5% | Dec 20, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution du... |
| CVE-2021-44916 | MEDIUM | 6.1 | 3.7% | Dec 20, 2021 | Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad... |
| CVE-2021-44790 | CRITICAL | 9.8 | 97.1% | Dec 20, 2021 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from ... |
| CVE-2021-44224 | HIGH | 8.2 | 82.3% | Dec 20, 2021 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference... |
| CVE-2021-41561 | HIGH | 7.5 | 3.1% | Dec 20, 2021 | Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet f... |
| CVE-2021-44858 | HIGH | 7.5 | 1.3% | Dec 20, 2021 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us... |
| CVE-2021-44554 | MEDIUM | 5.3 | 1.0% | Dec 20, 2021 | Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /... |
| CVE-2021-44263 | MEDIUM | 5.4 | 0.6% | Dec 20, 2021 | Gurock TestRail before 7.2.4 mishandles HTML escaping. |
| CVE-2021-42913 | HIGH | 7.5 | 1.8% | Dec 20, 2021 | The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and clea... |
| CVE-2021-44732 | CRITICAL | 9.8 | 2.6% | Dec 20, 2021 | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_sessi... |
| CVE-2021-44164 | CRITICAL | 9.8 | 2.1% | Dec 20, 2021 | Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allo... |
| CVE-2021-44163 | MEDIUM | 6.1 | 0.8% | Dec 20, 2021 | Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attac... |
| CVE-2021-44162 | HIGH | 7.5 | 1.7% | Dec 20, 2021 | Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has imprope... |
| CVE-2021-44159 | CRITICAL | 9.8 | 3.4% | Dec 20, 2021 | 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary fil... |
| CVE-2021-4136 | HIGH | 7.8 | 1.8% | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-45041 | HIGH | 8.8 | 2.2% | Dec 19, 2021 | SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project mo... |
| CVE-2021-43083 | HIGH | 8.8 | 1.9% | Dec 19, 2021 | Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow f... |
| CVE-2021-45105 | MEDIUM | 5.9 | 100.0% | Dec 18, 2021 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursio... |
| CVE-2021-4131 | HIGH | 8.8 | 0.5% | Dec 18, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4130 | HIGH | 8.8 | 0.5% | Dec 18, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now