2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44045 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.... |
| CVE-2021-44044 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022.... |
| CVE-2021-37253 | HIGH | 7.5 | 2.8% | Dec 5, 2021 | M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range o... |
| CVE-2021-4005 | MEDIUM | 4.3 | 0.4% | Dec 4, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-43415 | HIGH | 8.8 | 1.2% | Dec 3, 2021 | HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenti... |
| CVE-2021-35415 | MEDIUM | 4.8 | 0.9% | Dec 3, 2021 | A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte... |
| CVE-2021-35414 | CRITICAL | 9.8 | 1.8% | Dec 3, 2021 | Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload... |
| CVE-2021-35413 | HIGH | 8.8 | 2.5% | Dec 3, 2021 | A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated a... |
| CVE-2021-44349 | CRITICAL | 9.8 | 1.1% | Dec 3, 2021 | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.cl... |
| CVE-2021-44348 | CRITICAL | 9.8 | 1.1% | Dec 3, 2021 | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class... |
| CVE-2021-35346 | CRITICAL | 9.8 | 1.7% | Dec 3, 2021 | tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function HevcSpsUnit::short_term_ref_pic_... |
| CVE-2021-35344 | CRITICAL | 9.8 | 1.7% | Dec 3, 2021 | tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function BitStreamReader::getCurVal in bi... |
| CVE-2021-23758 | CRITICAL | 9.8 | 88.8% | Dec 3, 2021 | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserial... |
| CVE-2021-23562 | HIGH | 8.8 | 1.0% | Dec 3, 2021 | This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An att... |
| CVE-2021-44352 | CRITICAL | 9.8 | 13.4% | Dec 3, 2021 | A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in... |
| CVE-2021-44347 | CRITICAL | 9.8 | 1.1% | Dec 3, 2021 | SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php. |
| CVE-2021-38909 | MEDIUM | 5.4 | 0.7% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-29867 | MEDIUM | 5.4 | 0.8% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should ... |
| CVE-2021-29756 | HIGH | 8.8 | 0.6% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which cou... |
| CVE-2021-29719 | MEDIUM | 5.3 | 1.2% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifyin... |
| CVE-2021-29716 | MEDIUM | 6.5 | 0.9% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user shou... |
| CVE-2021-20493 | MEDIUM | 6.1 | 0.9% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-20470 | HIGH | 7.5 | 1.4% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes ... |
| CVE-2021-43991 | MEDIUM | 5.4 | 0.5% | Dec 3, 2021 | The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability ... |
| CVE-2021-3980 | HIGH | 7.5 | 1.6% | Dec 3, 2021 | elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now