2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0674 | MEDIUM | 5.5 | 0.5% | Dec 17, 2021 | In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local infor... |
| CVE-2021-0673 | HIGH | 7.8 | 0.7% | Dec 17, 2021 | In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local ... |
| CVE-2021-44035 | HIGH | 7.8 | 0.6% | Dec 17, 2021 | Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and... |
| CVE-2021-41451 | HIGH | 7.5 | 3.2% | Dec 17, 2021 | A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unau... |
| CVE-2021-45042 | MEDIUM | 4.9 | 1.4% | Dec 17, 2021 | In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Int... |
| CVE-2021-42584 | MEDIUM | 5.4 | 0.7% | Dec 17, 2021 | A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32. |
| CVE-2021-4132 | MEDIUM | 5.4 | 0.6% | Dec 17, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-43678 | MEDIUM | 6.1 | 0.8% | Dec 17, 2021 | Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php. |
| CVE-2021-44145 | MEDIUM | 6.5 | 1.7% | Dec 17, 2021 | In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if ... |
| CVE-2021-36780 | HIGH | 8.1 | 0.5% | Dec 17, 2021 | A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to... |
| CVE-2021-36779 | CRITICAL | 9.6 | 0.7% | Dec 17, 2021 | A Missing Authentication for Critical Function vulnerability in SUSE Longhorn allows any workload in the cluster to exec... |
| CVE-2021-45038 | MEDIUM | 5.3 | 1.4% | Dec 17, 2021 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=r... |
| CVE-2021-44857 | MEDIUM | 6.5 | 0.9% | Dec 17, 2021 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us... |
| CVE-2021-41843 | MEDIUM | 6.5 | 13.7% | Dec 17, 2021 | An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker ... |
| CVE-2021-3179 | MEDIUM | 5.5 | 0.4% | Dec 16, 2021 | GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authenticatio... |
| CVE-2021-26800 | MEDIUM | 6.5 | 0.4% | Dec 16, 2021 | Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using... |
| CVE-2021-44317 | MEDIUM | 5.4 | 0.5% | Dec 16, 2021 | In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting ... |
| CVE-2021-44315 | HIGH | 7.5 | 1.7% | Dec 16, 2021 | In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to ... |
| CVE-2021-43837 | CRITICAL | 9.1 | 5.0% | Dec 16, 2021 | vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versio... |
| CVE-2021-43812 | MEDIUM | 6.1 | 0.7% | Dec 16, 2021 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 d... |
| CVE-2021-42550 | MEDIUM | 6.6 | 4.4% | Dec 16, 2021 | In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could... |
| CVE-2021-41262 | HIGH | 8.8 | 1.1% | Dec 16, 2021 | Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions... |
| CVE-2021-41261 | MEDIUM | 4.8 | 0.6% | Dec 16, 2021 | Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions... |
| CVE-2021-41028 | HIGH | 7.5 | 0.2% | Dec 16, 2021 | A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 ... |
| CVE-2021-38244 | HIGH | 7.5 | 1.2% | Dec 16, 2021 | A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now