2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20693 | HIGH | 7.5 | 1.1% | Apr 26, 2021 | Improper access control vulnerability in Gurunavi App for Android ver.10.0.10 and earlier and for iOS ver.11.1.2 and ear... |
| CVE-2021-31762 | HIGH | 8.8 | 8.8% | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users fea... |
| CVE-2021-31760 | HIGH | 8.8 | 8.5% | Apr 25, 2021 | Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to achieve Remote Command Execution (RCE) through Webmin's... |
| CVE-2021-31718 | HIGH | 8.8 | 1.0% | Apr 25, 2021 | The server in npupnp before 4.1.4 is affected by DNS rebinding in the embedded web server (including UPnP SOAP and GENA ... |
| CVE-2021-31795 | HIGH | 7 | 0.4% | Apr 24, 2021 | The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allo... |
| CVE-2021-31598 | HIGH | 7.5 | 1.4% | Apr 24, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling whi... |
| CVE-2021-31791 | HIGH | 7.5 | 0.6% | Apr 23, 2021 | In Hardware Sentry KM before 10.0.01 for BMC PATROL, a cleartext password may be discovered after a failure or timeout o... |
| CVE-2021-31584 | HIGH | 8.8 | 0.9% | Apr 23, 2021 | Sipwise C5 NGCP www_csc version 3.6.4 up to and including platform NGCP CE mr3.8.13 allows call/click2dial CSRF attacks ... |
| CVE-2021-25899 | HIGH | 7.5 | 12.2% | Apr 23, 2021 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a craft... |
| CVE-2021-25898 | HIGH | 7.5 | 0.9% | Apr 23, 2021 | An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-c... |
| CVE-2021-31780 | HIGH | 7.5 | 1.0% | Apr 23, 2021 | In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure... |
| CVE-2021-20089 | HIGH | 8.8 | 1.6% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicio... |
| CVE-2021-20086 | HIGH | 8.8 | 6.1% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a m... |
| CVE-2021-20085 | HIGH | 8.8 | 1.6% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0... |
| CVE-2021-20083 | HIGH | 8.8 | 4.2% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object ... |
| CVE-2021-29469 | HIGH | 7.5 | 1.7% | Apr 23, 2021 | Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to... |
| CVE-2021-22682 | HIGH | 7.8 | 0.2% | Apr 23, 2021 | Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permis... |
| CVE-2021-22678 | HIGH | 7.8 | 1.0% | Apr 23, 2021 | Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This c... |
| CVE-2021-22204 | HIGH | 7.8 | 100.0% | Apr 23, 2021 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec... |
| CVE-2021-20088 | HIGH | 8.8 | 1.4% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows ... |
| CVE-2021-20087 | HIGH | 8.8 | 2.1% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows... |
| CVE-2021-20084 | HIGH | 8.8 | 1.4% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta a... |
| CVE-2021-31540 | HIGH | 7.1 | 0.4% | Apr 23, 2021 | Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files i... |
| CVE-2021-31410 | HIGH | 7.5 | 1.7% | Apr 23, 2021 | Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote ... |
| CVE-2021-31408 | HIGH | 7.1 | 0.3% | Apr 23, 2021 | Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now