2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43676 | CRITICAL | 9.8 | 1.4% | Dec 3, 2021 | matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php. |
| CVE-2021-44278 | CRITICAL | 9.8 | 1.4% | Dec 3, 2021 | Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php. |
| CVE-2021-43674 | CRITICAL | 9.8 | 1.4% | Dec 3, 2021 | ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only ... |
| CVE-2021-43673 | MEDIUM | 6.1 | 0.6% | Dec 3, 2021 | dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of th... |
| CVE-2021-4000 | MEDIUM | 6.1 | 0.8% | Dec 3, 2021 | showdoc is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-44022 | MEDIUM | 5.5 | 0.2% | Dec 3, 2021 | A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected ins... |
| CVE-2021-44021 | HIGH | 7.8 | 0.3% | Dec 3, 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker... |
| CVE-2021-44020 | HIGH | 7.8 | 0.3% | Dec 3, 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker... |
| CVE-2021-44019 | HIGH | 7.8 | 0.3% | Dec 3, 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker... |
| CVE-2021-43772 | MEDIUM | 5.5 | 0.2% | Dec 3, 2021 | Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be ... |
| CVE-2021-25785 | MEDIUM | 4.8 | 0.6% | Dec 2, 2021 | Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management colum... |
| CVE-2021-25784 | HIGH | 7.2 | 1.1% | Dec 2, 2021 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article. |
| CVE-2021-25783 | HIGH | 7.2 | 1.1% | Dec 2, 2021 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search. |
| CVE-2021-28237 | CRITICAL | 9.8 | 1.4% | Dec 2, 2021 | LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13. |
| CVE-2021-28236 | HIGH | 7.5 | 1.2% | Dec 2, 2021 | LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c. |
| CVE-2021-43327 | MEDIUM | 4.6 | 0.3% | Dec 2, 2021 | An issue was discovered on Renesas RX65 and RX65N devices. With a VCC glitch, an attacker can extract the security ID ke... |
| CVE-2021-44050 | MEDIUM | 6.5 | 0.9% | Dec 2, 2021 | CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due ... |
| CVE-2021-40334 | HIGH | 7.5 | 1.0% | Dec 2, 2021 | Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 all... |
| CVE-2021-40333 | HIGH | 7.1 | 0.6% | Dec 2, 2021 | Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access ... |
| CVE-2021-43795 | HIGH | 7.5 | 1.6% | Dec 2, 2021 | Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local ... |
| CVE-2021-44518 | MEDIUM | 6.8 | 0.3% | Dec 2, 2021 | An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing... |
| CVE-2021-3944 | MEDIUM | 6.8 | 0.6% | Dec 2, 2021 | bookstack is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-23264 | CRITICAL | 9.1 | 1.1% | Dec 2, 2021 | Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete... |
| CVE-2021-23263 | HIGH | 7.5 | 1.6% | Dec 2, 2021 | Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and so... |
| CVE-2021-23262 | HIGH | 7.2 | 0.6% | Dec 2, 2021 | Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now