2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20042 | CRITICAL | 9.8 | 2.7% | Dec 8, 2021 | An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass f... |
| CVE-2021-20041 | HIGH | 7.5 | 6.8% | Dec 8, 2021 | An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 ... |
| CVE-2021-20040 | HIGH | 7.5 | 25.8% | Dec 8, 2021 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload ... |
| CVE-2021-20039 | HIGH | 8.8 | 78.1% | Dec 8, 2021 | Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo... |
| CVE-2021-20038 | CRITICAL | 9.8 | 99.9% | Dec 8, 2021 | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows ... |
| CVE-2021-44726 | MEDIUM | 6.1 | 0.7% | Dec 8, 2021 | KNIME Server before 4.13.4 allows XSS via the old WebPortal login page. |
| CVE-2021-44725 | HIGH | 7.5 | 1.5% | Dec 8, 2021 | KNIME Server before 4.13.4 allows directory traversal in a request for a client profile. |
| CVE-2021-41311 | HIGH | 7.5 | 0.8% | Dec 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that ... |
| CVE-2021-41309 | MEDIUM | 5.3 | 0.8% | Dec 8, 2021 | Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access... |
| CVE-2021-3370 | MEDIUM | 6.1 | 0.6% | Dec 8, 2021 | DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php. |
| CVE-2021-44420 | HIGH | 7.3 | 2.3% | Dec 8, 2021 | In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines cou... |
| CVE-2021-43808 | MEDIUM | 6.1 | 0.8% | Dec 8, 2021 | Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-s... |
| CVE-2021-44148 | MEDIUM | 6.1 | 0.6% | Dec 7, 2021 | GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an a... |
| CVE-2021-43963 | HIGH | 8.1 | 0.5% | Dec 7, 2021 | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write dat... |
| CVE-2021-43810 | MEDIUM | 6.1 | 5.8% | Dec 7, 2021 | Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vu... |
| CVE-2021-42717 | HIGH | 7.5 | 3.2% | Dec 7, 2021 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thou... |
| CVE-2021-42567 | MEDIUM | 6.1 | 8.1% | Dec 7, 2021 | Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints. |
| CVE-2021-40578 | HIGH | 7.2 | 1.5% | Dec 7, 2021 | Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in P... |
| CVE-2021-44149 | HIGH | 7.8 | 0.3% | Dec 7, 2021 | An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL So... |
| CVE-2021-42688 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x2200... |
| CVE-2021-42687 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B... |
| CVE-2021-42686 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Acco... |
| CVE-2021-42685 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 . The IOCTL Handler 0x22005B in... |
| CVE-2021-42683 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B... |
| CVE-2021-42682 | HIGH | 8.8 | 0.5% | Dec 7, 2021 | An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B all... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now