2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43833 | HIGH | 8.8 | 0.8% | Dec 16, 2021 | eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh... |
| CVE-2021-45018 | MEDIUM | 6.1 | 0.6% | Dec 15, 2021 | Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admi... |
| CVE-2021-45017 | HIGH | 8.8 | 0.4% | Dec 15, 2021 | Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on... |
| CVE-2021-44350 | CRITICAL | 9.8 | 1.4% | Dec 15, 2021 | SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php. |
| CVE-2021-44116 | MEDIUM | 6.1 | 0.7% | Dec 15, 2021 | Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column t... |
| CVE-2021-4119 | CRITICAL | 9.8 | 26.9% | Dec 15, 2021 | bookstack is vulnerable to Improper Access Control |
| CVE-2021-45078 | HIGH | 7.8 | 1.3% | Dec 15, 2021 | stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-base... |
| CVE-2021-43836 | HIGH | 8.8 | 2.0% | Dec 15, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker ca... |
| CVE-2021-43835 | HIGH | 7.2 | 1.1% | Dec 15, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who... |
| CVE-2021-43831 | HIGH | 7.7 | 3.8% | Dec 15, 2021 | Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.... |
| CVE-2021-43806 | HIGH | 8.8 | 1.5% | Dec 15, 2021 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected v... |
| CVE-2021-43782 | HIGH | 7.2 | 1.4% | Dec 15, 2021 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a fol... |
| CVE-2021-41276 | HIGH | 7.2 | 1.5% | Dec 15, 2021 | Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected v... |
| CVE-2021-35490 | MEDIUM | 5.4 | 0.5% | Dec 15, 2021 | Thruk before 2.44 allows XSS for a quick command. |
| CVE-2021-29847 | MEDIUM | 5.9 | 1.0% | Dec 15, 2021 | BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user t... |
| CVE-2021-27859 | HIGH | 8.8 | 1.6% | Dec 15, 2021 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t... |
| CVE-2021-27858 | MEDIUM | 5.3 | 2.7% | Dec 15, 2021 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t... |
| CVE-2021-27857 | HIGH | 7.5 | 1.8% | Dec 15, 2021 | A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t... |
| CVE-2021-27856 | CRITICAL | 9.8 | 5.6% | Dec 15, 2021 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" ... |
| CVE-2021-27855 | HIGH | 8.8 | 1.6% | Dec 15, 2021 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated atta... |
| CVE-2021-43935 | CRITICAL | 9.8 | 1.1% | Dec 15, 2021 | The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulner... |
| CVE-2021-39657 | MEDIUM | 4.4 | 0.2% | Dec 15, 2021 | In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. Thi... |
| CVE-2021-39656 | MEDIUM | 6.7 | 0.1% | Dec 15, 2021 | In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local ... |
| CVE-2021-39655 | CRITICAL | 9.8 | 0.5% | Dec 15, 2021 | Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A |
| CVE-2021-39653 | HIGH | 7.8 | 0.1% | Dec 15, 2021 | In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now