2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23261 | MEDIUM | 4.9 | 0.6% | Dec 2, 2021 | Authenticated administrators may override the system configuration file and cause a denial of service. |
| CVE-2021-23260 | MEDIUM | 5.4 | 0.4% | Dec 2, 2021 | Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and ... |
| CVE-2021-23259 | HIGH | 7.2 | 0.7% | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib... |
| CVE-2021-23258 | HIGH | 7.2 | 0.7% | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SP... |
| CVE-2021-43679 | CRITICAL | 9.8 | 1.6% | Dec 2, 2021 | ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php. |
| CVE-2021-43682 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseControll... |
| CVE-2021-43686 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will ter... |
| CVE-2021-43683 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will termina... |
| CVE-2021-43681 | MEDIUM | 6.1 | 0.6% | Dec 2, 2021 | SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit... |
| CVE-2021-26777 | CRITICAL | 9.8 | 2.4% | Dec 2, 2021 | Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concent... |
| CVE-2021-44227 | HIGH | 8.8 | 0.7% | Dec 2, 2021 | In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that tok... |
| CVE-2021-43791 | MEDIUM | 5.3 | 0.6% | Dec 2, 2021 | Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected ver... |
| CVE-2021-42711 | HIGH | 7.8 | 0.3% | Dec 1, 2021 | Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This fil... |
| CVE-2021-33274 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33271 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33270 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33269 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33268 | CRITICAL | 9.8 | 3.9% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33267 | CRITICAL | 9.8 | 3.8% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33266 | CRITICAL | 9.8 | 16.9% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-33265 | CRITICAL | 9.8 | 13.7% | Dec 1, 2021 | D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov... |
| CVE-2021-43794 | MEDIUM | 5.3 | 1.0% | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i.... |
| CVE-2021-43793 | MEDIUM | 4.3 | 0.8% | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users... |
| CVE-2021-43792 | MEDIUM | 4.3 | 0.8% | Dec 1, 2021 | Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us... |
| CVE-2021-43137 | HIGH | 8.8 | 0.5% | Dec 1, 2021 | Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now