2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41039 | HIGH | 7.5 | 1.3% | Dec 1, 2021 | In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property proper... |
| CVE-2021-43451 | CRITICAL | 9.8 | 2.1% | Dec 1, 2021 | SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /... |
| CVE-2021-38575 | HIGH | 8.1 | 1.9% | Dec 1, 2021 | NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. |
| CVE-2021-42776 | HIGH | 7.7 | 0.8% | Dec 1, 2021 | CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import. |
| CVE-2021-29863 | MEDIUM | 4.3 | 0.5% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacke... |
| CVE-2021-29849 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2021-29779 | MEDIUM | 5.9 | 1.2% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exc... |
| CVE-2021-20400 | HIGH | 7.5 | 0.7% | Dec 1, 2021 | IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h... |
| CVE-2021-44480 | HIGH | 8.1 | 1.0% | Dec 1, 2021 | Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen... |
| CVE-2021-43687 | MEDIUM | 6.1 | 1.4% | Dec 1, 2021 | chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an atta... |
| CVE-2021-43685 | CRITICAL | 9.8 | 1.2% | Dec 1, 2021 | libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/r... |
| CVE-2021-26334 | CRITICAL | 9.9 | 1.2% | Dec 1, 2021 | The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may le... |
| CVE-2021-20611 | HIGH | 7.5 | 3.0% | Dec 1, 2021 | Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/0... |
| CVE-2021-20610 | HIGH | 7.5 | 3.1% | Dec 1, 2021 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU... |
| CVE-2021-20609 | HIGH | 7.5 | 3.1% | Dec 1, 2021 | Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Seri... |
| CVE-2021-44479 | MEDIUM | 5.5 | 0.3% | Dec 1, 2021 | NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of ... |
| CVE-2021-43689 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controll... |
| CVE-2021-40154 | MEDIUM | 5.5 | 0.7% | Dec 1, 2021 | NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration req... |
| CVE-2021-44279 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php. |
| CVE-2021-44277 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php. |
| CVE-2021-25967 | MEDIUM | 5.4 | 0.5% | Dec 1, 2021 | In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile pictur... |
| CVE-2021-44280 | CRITICAL | 9.8 | 1.9% | Dec 1, 2021 | attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the make... |
| CVE-2021-43690 | MEDIUM | 6.1 | 0.6% | Dec 1, 2021 | YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will ter... |
| CVE-2021-3983 | MEDIUM | 6.1 | 0.8% | Dec 1, 2021 | kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3964 | MEDIUM | 5.9 | 0.8% | Dec 1, 2021 | elgg is vulnerable to Authorization Bypass Through User-Controlled Key |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now