2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45105 | MEDIUM | 5.9 | 100.0% | Dec 18, 2021 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursio... |
| CVE-2021-4131 | HIGH | 8.8 | 0.5% | Dec 18, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4130 | HIGH | 8.8 | 0.5% | Dec 18, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-41500 | HIGH | 7.5 | 1.2% | Dec 17, 2021 | Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholm... |
| CVE-2021-41499 | HIGH | 7.5 | 1.4% | Dec 17, 2021 | Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remo... |
| CVE-2021-41498 | HIGH | 7.5 | 1.1% | Dec 17, 2021 | Buffer overflow in ajaxsoundstudio.com Pyo < and 1.03 in the Server_jack_init function. which allows attackers to cond... |
| CVE-2021-41497 | HIGH | 7.5 | 1.0% | Dec 17, 2021 | Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows atta... |
| CVE-2021-41496 | MEDIUM | 5.5 | 0.4% | Dec 17, 2021 | Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a... |
| CVE-2021-41495 | MEDIUM | 5.3 | 1.2% | Dec 17, 2021 | Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due t... |
| CVE-2021-23814 | HIGH | 8.8 | 1.8% | Dec 17, 2021 | This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficien... |
| CVE-2021-23803 | CRITICAL | 9.8 | 1.6% | Dec 17, 2021 | This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the securit... |
| CVE-2021-23797 | CRITICAL | 9.8 | 1.7% | Dec 17, 2021 | All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. |
| CVE-2021-23450 | CRITICAL | 9.8 | 30.4% | Dec 17, 2021 | All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. |
| CVE-2021-43840 | MEDIUM | 6.5 | 1.9% | Dec 17, 2021 | message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message... |
| CVE-2021-43838 | HIGH | 7.5 | 1.4% | Dec 17, 2021 | jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users... |
| CVE-2021-34141 | MEDIUM | 5.3 | 1.6% | Dec 17, 2021 | An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly ... |
| CVE-2021-33430 | MEDIUM | 5.3 | 1.1% | Dec 17, 2021 | A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifyin... |
| CVE-2021-4011 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-4010 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-4009 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-4008 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t... |
| CVE-2021-40853 | HIGH | 7.2 | 0.8% | Dec 17, 2021 | TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could ex... |
| CVE-2021-40852 | MEDIUM | 6.1 | 0.7% | Dec 17, 2021 | TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to... |
| CVE-2021-40851 | HIGH | 7.5 | 1.3% | Dec 17, 2021 | TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. Th... |
| CVE-2021-40850 | CRITICAL | 9.8 | 0.9% | Dec 17, 2021 | TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now