2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24705 | MEDIUM | 4.8 | 0.3% | Dec 13, 2021 | The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape ... |
| CVE-2021-20867 | MEDIUM | 6.5 | 1.4% | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au... |
| CVE-2021-20866 | MEDIUM | 6.5 | 1.7% | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au... |
| CVE-2021-20865 | HIGH | 7.5 | 2.5% | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au... |
| CVE-2021-44155 | MEDIUM | 5.3 | 1.8% | Dec 13, 2021 | An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response i... |
| CVE-2021-44154 | HIGH | 7.2 | 1.8% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_... |
| CVE-2021-44153 | HIGH | 7.2 | 2.0% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable a... |
| CVE-2021-44152 | CRITICAL | 9.8 | 58.6% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a... |
| CVE-2021-44151 | HIGH | 7.5 | 2.5% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessi... |
| CVE-2021-40858 | MEDIUM | 4.9 | 2.4% | Dec 13, 2021 | Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin pa... |
| CVE-2021-40857 | HIGH | 8.8 | 2.0% | Dec 13, 2021 | Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring. |
| CVE-2021-40856 | HIGH | 7.5 | 51.1% | Dec 13, 2021 | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring. |
| CVE-2021-44848 | MEDIUM | 5.3 | 23.1% | Dec 13, 2021 | In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques... |
| CVE-2021-44847 | CRITICAL | 9.8 | 4.0% | Dec 13, 2021 | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.... |
| CVE-2021-44833 | CRITICAL | 9.8 | 1.6% | Dec 12, 2021 | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. |
| CVE-2021-44515 | CRITICAL | 9.8 | 99.9% | Dec 12, 2021 | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server... |
| CVE-2021-41805 | HIGH | 8.8 | 34.8% | Dec 12, 2021 | HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. A... |
| CVE-2021-4097 | MEDIUM | 5.4 | 0.8% | Dec 12, 2021 | phpservermon is vulnerable to Improper Neutralization of CRLF Sequences |
| CVE-2021-4092 | MEDIUM | 4.3 | 0.4% | Dec 11, 2021 | yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-41242 | HIGH | 8.1 | 1.4% | Dec 10, 2021 | OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 1... |
| CVE-2021-26340 | HIGH | 8.4 | 0.2% | Dec 10, 2021 | A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to fl... |
| CVE-2021-43815 | MEDIUM | 4.3 | 1.8% | Dec 10, 2021 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a di... |
| CVE-2021-4089 | MEDIUM | 4.3 | 0.7% | Dec 10, 2021 | snipe-it is vulnerable to Improper Access Control |
| CVE-2021-23700 | CRITICAL | 9.8 | 1.2% | Dec 10, 2021 | All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function. |
| CVE-2021-23663 | CRITICAL | 9.8 | 1.2% | Dec 10, 2021 | All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now