2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41027 | HIGH | 7.8 | 0.2% | Dec 8, 2021 | A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute ... |
| CVE-2021-41024 | HIGH | 7.5 | 1.6% | Dec 8, 2021 | A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may al... |
| CVE-2021-41015 | MEDIUM | 6.1 | 0.8% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.... |
| CVE-2021-41014 | HIGH | 7.5 | 1.1% | Dec 8, 2021 | A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthentic... |
| CVE-2021-36191 | MEDIUM | 5.4 | 0.5% | Dec 8, 2021 | A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below all... |
| CVE-2021-26109 | CRITICAL | 9.8 | 1.8% | Dec 8, 2021 | An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an u... |
| CVE-2021-26108 | HIGH | 7.5 | 1.0% | Dec 8, 2021 | A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retri... |
| CVE-2021-44557 | CRITICAL | 9.1 | 1.3% | Dec 8, 2021 | National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External ... |
| CVE-2021-44556 | CRITICAL | 9.1 | 1.3% | Dec 8, 2021 | National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Enti... |
| CVE-2021-43067 | MEDIUM | 6.5 | 1.1% | Dec 8, 2021 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2... |
| CVE-2021-42760 | HIGH | 8.8 | 0.9% | Dec 8, 2021 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-42752 | MEDIUM | 5.4 | 0.5% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-41029 | MEDIUM | 5.4 | 0.5% | Dec 8, 2021 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.... |
| CVE-2021-32591 | MEDIUM | 5.3 | 0.9% | Dec 8, 2021 | A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan... |
| CVE-2021-26103 | HIGH | 8.8 | 0.4% | Dec 8, 2021 | An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.... |
| CVE-2021-4050 | MEDIUM | 6.1 | 0.9% | Dec 8, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-42758 | HIGH | 8.8 | 2.0% | Dec 8, 2021 | An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote att... |
| CVE-2021-42757 | MEDIUM | 6.7 | 0.5% | Dec 8, 2021 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allo... |
| CVE-2021-36180 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management i... |
| CVE-2021-31850 | MEDIUM | 6.1 | 1.0% | Dec 8, 2021 | A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator ... |
| CVE-2021-26110 | HIGH | 7.8 | 0.2% | Dec 8, 2021 | An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.... |
| CVE-2021-20047 | HIGH | 7.8 | 0.9% | Dec 8, 2021 | SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerabili... |
| CVE-2021-20045 | CRITICAL | 9.8 | 25.2% | Dec 8, 2021 | A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated a... |
| CVE-2021-20044 | HIGH | 8.8 | 40.1% | Dec 8, 2021 | A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker ... |
| CVE-2021-20043 | HIGH | 8.8 | 23.3% | Dec 8, 2021 | A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacke... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now