2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43803 | HIGH | 7.5 | 44.8% | Dec 10, 2021 | Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to ... |
| CVE-2021-43802 | HIGH | 8.8 | 2.0% | Dec 9, 2021 | Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file th... |
| CVE-2021-43982 | HIGH | 7.8 | 9.6% | Dec 9, 2021 | Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an... |
| CVE-2021-37861 | HIGH | 7.5 | 0.9% | Dec 9, 2021 | Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails. |
| CVE-2021-4033 | MEDIUM | 6.5 | 0.5% | Dec 9, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-44514 | CRITICAL | 9.8 | 5.4% | Dec 9, 2021 | OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. |
| CVE-2021-43608 | CRITICAL | 9.8 | 2.4% | Dec 9, 2021 | Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIM... |
| CVE-2021-43797 | MEDIUM | 6.5 | 2.7% | Dec 9, 2021 | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan... |
| CVE-2021-43703 | CRITICAL | 9.8 | 1.8% | Dec 9, 2021 | An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling Java... |
| CVE-2021-41265 | HIGH | 8.8 | 1.3% | Dec 9, 2021 | Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentica... |
| CVE-2021-40282 | HIGH | 8.8 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary... |
| CVE-2021-40281 | HIGH | 8.8 | 1.1% | Dec 9, 2021 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary use... |
| CVE-2021-39002 | HIGH | 7.5 | 0.9% | Dec 9, 2021 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expec... |
| CVE-2021-38951 | HIGH | 7.5 | 1.5% | Dec 9, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia... |
| CVE-2021-38931 | MEDIUM | 6.5 | 1.2% | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclos... |
| CVE-2021-38926 | MEDIUM | 5.5 | 0.3% | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2021-29678 | HIGH | 8.7 | 1.1% | Dec 9, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user wit... |
| CVE-2021-22568 | HIGH | 8.8 | 0.9% | Dec 9, 2021 | When using the dart pub publish command to publish a package to a third-party package server, the request would be authe... |
| CVE-2021-20373 | HIGH | 7.5 | 1.5% | Dec 9, 2021 | IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as un... |
| CVE-2021-4038 | MEDIUM | 4.8 | 0.6% | Dec 9, 2021 | Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote ... |
| CVE-2021-41697 | MEDIUM | 6.1 | 0.7% | Dec 9, 2021 | A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description pa... |
| CVE-2021-41696 | MEDIUM | 6.5 | 0.9% | Dec 9, 2021 | An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password r... |
| CVE-2021-41695 | CRITICAL | 9.8 | 1.2% | Dec 9, 2021 | An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. . |
| CVE-2021-41694 | CRITICAL | 9.8 | 1.3% | Dec 9, 2021 | An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in req... |
| CVE-2021-41246 | HIGH | 8.8 | 0.9% | Dec 9, 2021 | Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now