2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37262 | HIGH | 7.5 | 1.0% | Dec 16, 2021 | JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. |
| CVE-2021-41962 | MEDIUM | 4.8 | 0.6% | Dec 16, 2021 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fu... |
| CVE-2021-41260 | HIGH | 8.8 | 0.4% | Dec 16, 2021 | Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions... |
| CVE-2021-42912 | HIGH | 8.8 | 14.1% | Dec 16, 2021 | FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows th... |
| CVE-2021-3960 | HIGH | 7.8 | 0.3% | Dec 16, 2021 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer compone... |
| CVE-2021-3959 | HIGH | 7.5 | 1.7% | Dec 16, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To... |
| CVE-2021-4124 | MEDIUM | 6.1 | 0.9% | Dec 16, 2021 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-40835 | MEDIUM | 4.3 | 0.7% | Dec 16, 2021 | An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafte... |
| CVE-2021-4123 | MEDIUM | 6.5 | 0.5% | Dec 16, 2021 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4121 | MEDIUM | 6.1 | 0.8% | Dec 16, 2021 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-45102 | HIGH | 8.8 | 0.9% | Dec 16, 2021 | An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon... |
| CVE-2021-45101 | HIGH | 8.1 | 0.9% | Dec 16, 2021 | An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-li... |
| CVE-2021-45100 | HIGH | 7.5 | 0.9% | Dec 16, 2021 | The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even tho... |
| CVE-2021-45099 | HIGH | 8.8 | 1.3% | Dec 16, 2021 | The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an atta... |
| CVE-2021-45098 | HIGH | 7.5 | 1.8% | Dec 16, 2021 | An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an R... |
| CVE-2021-45097 | MEDIUM | 5.5 | 0.2% | Dec 16, 2021 | KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's passwo... |
| CVE-2021-45096 | MEDIUM | 4.3 | 1.1% | Dec 16, 2021 | KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (... |
| CVE-2021-45095 | MEDIUM | 5.5 | 0.3% | Dec 16, 2021 | pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak. |
| CVE-2021-45092 | CRITICAL | 9.8 | 40.0% | Dec 16, 2021 | Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi... |
| CVE-2021-45088 | MEDIUM | 6.1 | 1.4% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page. |
| CVE-2021-45087 | MEDIUM | 6.1 | 1.5% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used,... |
| CVE-2021-45086 | MEDIUM | 6.1 | 1.3% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used... |
| CVE-2021-45085 | MEDIUM | 6.1 | 1.5% | Dec 16, 2021 | XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-a... |
| CVE-2021-44023 | HIGH | 7.1 | 0.4% | Dec 16, 2021 | A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products c... |
| CVE-2021-43834 | CRITICAL | 9.8 | 1.0% | Dec 16, 2021 | eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now