2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40452 | HIGH | 7.8 | 2.5% | Dec 15, 2021 | HEVC Video Extensions Remote Code Execution Vulnerability |
| CVE-2021-40441 | HIGH | 7.8 | 0.7% | Dec 15, 2021 | Windows Media Center Elevation of Privilege Vulnerability |
| CVE-2021-4116 | MEDIUM | 5.4 | 0.5% | Dec 15, 2021 | yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-20330 | MEDIUM | 6.5 | 1.0% | Dec 15, 2021 | An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed... |
| CVE-2021-4111 | MEDIUM | 4.3 | 0.6% | Dec 15, 2021 | yetiforcecrm is vulnerable to Business Logic Errors |
| CVE-2021-45043 | HIGH | 7.5 | 33.1% | Dec 15, 2021 | HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L... |
| CVE-2021-43326 | HIGH | 7.8 | 1.2% | Dec 15, 2021 | Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory. |
| CVE-2021-43325 | HIGH | 7.8 | 0.2% | Dec 15, 2021 | Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a ... |
| CVE-2021-43113 | CRITICAL | 9.8 | 5.2% | Dec 15, 2021 | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mi... |
| CVE-2021-42945 | CRITICAL | 9.8 | 1.0% | Dec 15, 2021 | A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php. |
| CVE-2021-42220 | MEDIUM | 5.4 | 0.9% | Dec 15, 2021 | A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation r... |
| CVE-2021-41560 | CRITICAL | 9.8 | 11.1% | Dec 15, 2021 | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUti... |
| CVE-2021-41557 | MEDIUM | 5.4 | 0.8% | Dec 15, 2021 | Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a use... |
| CVE-2021-40827 | HIGH | 7.8 | 1.2% | Dec 15, 2021 | Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block ... |
| CVE-2021-40826 | HIGH | 7.8 | 1.2% | Dec 15, 2021 | Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsin... |
| CVE-2021-40171 | MEDIUM | 5.3 | 0.9% | Dec 15, 2021 | The absence of notifications regarding an ongoing RF jamming attack in the SecuritasHome home alarm system, version HPGW... |
| CVE-2021-40170 | MEDIUM | 6.8 | 0.9% | Dec 15, 2021 | An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30... |
| CVE-2021-38701 | MEDIUM | 4.8 | 0.5% | Dec 15, 2021 | Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; ... |
| CVE-2021-36450 | MEDIUM | 6.1 | 69.4% | Dec 15, 2021 | Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter. |
| CVE-2021-26787 | MEDIUM | 6.1 | 1.0% | Dec 15, 2021 | A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion)... |
| CVE-2021-41871 | MEDIUM | 5.4 | 0.5% | Dec 15, 2021 | An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes ... |
| CVE-2021-41870 | HIGH | 8.8 | 1.1% | Dec 15, 2021 | An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can b... |
| CVE-2021-41844 | CRITICAL | 9.8 | 1.1% | Dec 15, 2021 | Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data. |
| CVE-2021-4110 | HIGH | 7.5 | 1.6% | Dec 15, 2021 | mruby is vulnerable to NULL Pointer Dereference |
| CVE-2021-43827 | MEDIUM | 4.3 | 0.8% | Dec 14, 2021 | discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote w... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now