2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32592 | HIGH | 7.8 | 0.2% | Dec 1, 2021 | An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0,... |
| CVE-2021-4017 | HIGH | 8.8 | 0.6% | Dec 1, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-4015 | MEDIUM | 4.3 | 0.4% | Dec 1, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3994 | CRITICAL | 9.6 | 1.4% | Dec 1, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3993 | MEDIUM | 6.5 | 0.5% | Dec 1, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3992 | MEDIUM | 6.5 | 1.0% | Dec 1, 2021 | kimai2 is vulnerable to Improper Access Control |
| CVE-2021-3990 | MEDIUM | 6.5 | 0.9% | Dec 1, 2021 | showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) |
| CVE-2021-3989 | MEDIUM | 6.1 | 0.8% | Dec 1, 2021 | showdoc is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-3985 | CRITICAL | 9 | 1.2% | Dec 1, 2021 | kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3984 | HIGH | 7.8 | 1.5% | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-4019 | HIGH | 7.8 | 1.8% | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-4018 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-34599 | HIGH | 7.4 | 0.5% | Dec 1, 2021 | Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS ... |
| CVE-2021-20864 | HIGH | 8.8 | 0.5% | Dec 1, 2021 | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v... |
| CVE-2021-20863 | HIGH | 8 | 0.9% | Dec 1, 2021 | OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.2... |
| CVE-2021-20862 | MEDIUM | 4.3 | 0.4% | Dec 1, 2021 | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v... |
| CVE-2021-20861 | HIGH | 8.8 | 0.4% | Dec 1, 2021 | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmwa... |
| CVE-2021-20860 | HIGH | 8.8 | 0.5% | Dec 1, 2021 | Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GS... |
| CVE-2021-20859 | HIGH | 8 | 0.5% | Dec 1, 2021 | ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmwar... |
| CVE-2021-20858 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenti... |
| CVE-2021-20857 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenti... |
| CVE-2021-20856 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware ... |
| CVE-2021-20855 | MEDIUM | 5.4 | 0.6% | Dec 1, 2021 | Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware ... |
| CVE-2021-20854 | MEDIUM | 6.8 | 0.4% | Dec 1, 2021 | ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-ad... |
| CVE-2021-20853 | MEDIUM | 6.8 | 0.4% | Dec 1, 2021 | ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-ad... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now