2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23639 | CRITICAL | 9.8 | 5.3% | Dec 10, 2021 | The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matte... |
| CVE-2021-23561 | CRITICAL | 9.8 | 1.2% | Dec 10, 2021 | All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function. |
| CVE-2021-23463 | CRITICAL | 9.1 | 3.3% | Dec 10, 2021 | The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via ... |
| CVE-2021-31747 | MEDIUM | 4.8 | 0.3% | Dec 10, 2021 | Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-mid... |
| CVE-2021-27984 | HIGH | 8.1 | 2.5% | Dec 10, 2021 | In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files. |
| CVE-2021-27983 | CRITICAL | 9.8 | 3.5% | Dec 10, 2021 | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. |
| CVE-2021-43813 | MEDIUM | 4.3 | 58.0% | Dec 10, 2021 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains... |
| CVE-2021-38937 | MEDIUM | 6.5 | 1.0% | Dec 10, 2021 | IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a s... |
| CVE-2021-38917 | CRITICAL | 9.1 | 1.5% | Dec 10, 2021 | IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and... |
| CVE-2021-31746 | CRITICAL | 9.8 | 2.4% | Dec 10, 2021 | Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in ... |
| CVE-2021-31745 | HIGH | 7.5 | 1.2% | Dec 10, 2021 | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access ... |
| CVE-2021-37935 | HIGH | 7.5 | 1.4% | Dec 10, 2021 | An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenti... |
| CVE-2021-37934 | CRITICAL | 9.8 | 1.5% | Dec 10, 2021 | Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterpris... |
| CVE-2021-36911 | MEDIUM | 5.4 | 0.6% | Dec 10, 2021 | Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), cou... |
| CVE-2021-29214 | HIGH | 7.2 | 1.1% | Dec 10, 2021 | A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administr... |
| CVE-2021-3829 | MEDIUM | 6.1 | 0.8% | Dec 10, 2021 | openwhyd is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-40834 | MEDIUM | 4.3 | 0.7% | Dec 10, 2021 | A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a special... |
| CVE-2021-37189 | HIGH | 7.5 | 0.6% | Dec 10, 2021 | An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sen... |
| CVE-2021-37188 | HIGH | 8.8 | 0.5% | Dec 10, 2021 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firm... |
| CVE-2021-37187 | MEDIUM | 6.5 | 0.7% | Dec 10, 2021 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file... |
| CVE-2021-35978 | CRITICAL | 9.8 | 3.6% | Dec 10, 2021 | An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command exe... |
| CVE-2021-4084 | MEDIUM | 6.1 | 1.6% | Dec 10, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4082 | MEDIUM | 4.3 | 0.4% | Dec 10, 2021 | pimcore is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4081 | MEDIUM | 6.1 | 0.8% | Dec 10, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-44228 | CRITICAL | 10 | 100.0% | Dec 10, 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in con... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now