2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31632 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the Use... |
| CVE-2021-31631 | HIGH | 8.8 | 0.5% | Dec 6, 2021 | b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulne... |
| CVE-2021-4075 | HIGH | 7.2 | 0.9% | Dec 6, 2021 | snipe-it is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2021-40313 | HIGH | 8.8 | 1.1% | Dec 6, 2021 | Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager... |
| CVE-2021-40091 | CRITICAL | 9.8 | 1.1% | Dec 6, 2021 | An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654. |
| CVE-2021-37298 | — | — | — | Dec 6, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-36567 | CRITICAL | 9.8 | 2.4% | Dec 6, 2021 | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Stor... |
| CVE-2021-36564 | CRITICAL | 9.8 | 1.8% | Dec 6, 2021 | ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cach... |
| CVE-2021-43800 | HIGH | 7.5 | 1.7% | Dec 6, 2021 | Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is poss... |
| CVE-2021-43936 | CRITICAL | 9.8 | 35.8% | Dec 6, 2021 | The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automa... |
| CVE-2021-43931 | CRITICAL | 9.8 | 1.4% | Dec 6, 2021 | The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result ... |
| CVE-2021-43784 | MEDIUM | 5 | 1.7% | Dec 6, 2021 | runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is ... |
| CVE-2021-43781 | MEDIUM | 4.3 | 0.7% | Dec 6, 2021 | Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. ... |
| CVE-2021-39890 | CRITICAL | 9.8 | 1.0% | Dec 6, 2021 | It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 a... |
| CVE-2021-22170 | HIGH | 7.5 | 0.5% | Dec 6, 2021 | Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encr... |
| CVE-2021-36198 | HIGH | 7.5 | 1.1% | Dec 6, 2021 | Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data. |
| CVE-2021-35245 | MEDIUM | 6.8 | 1.2% | Dec 6, 2021 | When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed o... |
| CVE-2021-35242 | HIGH | 8.8 | 0.7% | Dec 6, 2021 | Serv-U server responds with valid CSRFToken when the request contains only Session. |
| CVE-2021-25041 | MEDIUM | 6.1 | 0.9% | Dec 6, 2021 | The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues v... |
| CVE-2021-24943 | CRITICAL | 9.8 | 7.5% | Dec 6, 2021 | The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the... |
| CVE-2021-24939 | MEDIUM | 6.1 | 0.8% | Dec 6, 2021 | The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login... |
| CVE-2021-24938 | MEDIUM | 6.1 | 0.8% | Dec 6, 2021 | The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_da... |
| CVE-2021-24935 | MEDIUM | 6.1 | 0.9% | Dec 6, 2021 | The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family pa... |
| CVE-2021-24931 | CRITICAL | 9.8 | 78.8% | Dec 6, 2021 | The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id paramet... |
| CVE-2021-24930 | MEDIUM | 5.4 | 0.6% | Dec 6, 2021 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name fi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now