2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44942 | MEDIUM | 4.3 | 0.3% | Dec 14, 2021 | glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_be... |
| CVE-2021-4108 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-44948 | — | — | — | Dec 14, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-44942. Reason: This candidate is a duplicate of ... |
| CVE-2021-43830 | HIGH | 8.8 | 0.9% | Dec 14, 2021 | OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection... |
| CVE-2021-43829 | HIGH | 8.8 | 59.2% | Dec 14, 2021 | PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlMana... |
| CVE-2021-43828 | HIGH | 7.5 | 1.4% | Dec 14, 2021 | PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper ... |
| CVE-2021-43821 | HIGH | 7.7 | 2.0% | Dec 14, 2021 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows... |
| CVE-2021-43051 | MEDIUM | 6.8 | 0.8% | Dec 14, 2021 | The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire ... |
| CVE-2021-39183 | MEDIUM | 6.1 | 0.7% | Dec 14, 2021 | Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are exe... |
| CVE-2021-34426 | HIGH | 7.8 | 0.2% | Dec 14, 2021 | A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase ... |
| CVE-2021-34425 | MEDIUM | 6.1 | 0.9% | Dec 14, 2021 | The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side re... |
| CVE-2021-4044 | HIGH | 7.5 | 50.1% | Dec 14, 2021 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. T... |
| CVE-2021-45046 | CRITICAL | 9 | 100.0% | Dec 14, 2021 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configu... |
| CVE-2021-43820 | MEDIUM | 5.9 | 1.0% | Dec 14, 2021 | Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize acces... |
| CVE-2021-40883 | CRITICAL | 9.8 | 3.0% | Dec 14, 2021 | A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. |
| CVE-2021-44043 | MEDIUM | 5.4 | 0.5% | Dec 14, 2021 | An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload function... |
| CVE-2021-44042 | CRITICAL | 9.8 | 1.1% | Dec 14, 2021 | An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the... |
| CVE-2021-44041 | CRITICAL | 9.8 | 1.7% | Dec 14, 2021 | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget a... |
| CVE-2021-43807 | MEDIUM | 6.5 | 1.4% | Dec 14, 2021 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP ... |
| CVE-2021-43388 | HIGH | 7.5 | 0.6% | Dec 14, 2021 | Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in ... |
| CVE-2021-40882 | MEDIUM | 6.1 | 0.8% | Dec 14, 2021 | A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the loca... |
| CVE-2021-38950 | HIGH | 7.8 | 0.2% | Dec 14, 2021 | IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to... |
| CVE-2021-4073 | HIGH | 8.1 | 7.0% | Dec 14, 2021 | The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including ... |
| CVE-2021-44549 | HIGH | 7.4 | 1.9% | Dec 14, 2021 | Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via S... |
| CVE-2021-44235 | MEDIUM | 6.7 | 0.3% | Dec 14, 2021 | Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now