2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43282 | MEDIUM | 6.5 | 0.7% | Nov 30, 2021 | An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone with... |
| CVE-2021-42099 | CRITICAL | 9.8 | 6.5% | Nov 30, 2021 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. |
| CVE-2021-26612 | CRITICAL | 9.8 | 1.2% | Nov 30, 2021 | An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remot... |
| CVE-2021-22095 | MEDIUM | 6.5 | 1.0% | Nov 30, 2021 | In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, wil... |
| CVE-2021-39000 | MEDIUM | 5.5 | 0.6% | Nov 30, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensiti... |
| CVE-2021-38999 | MEDIUM | 5.5 | 0.2% | Nov 30, 2021 | IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trac... |
| CVE-2021-38967 | MEDIUM | 6.7 | 0.3% | Nov 30, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Forc... |
| CVE-2021-38958 | MEDIUM | 5.5 | 0.2% | Nov 30, 2021 | IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force... |
| CVE-2021-43202 | CRITICAL | 9.8 | 1.1% | Nov 30, 2021 | In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases. |
| CVE-2021-43998 | MEDIUM | 6.5 | 1.0% | Nov 30, 2021 | HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-cr... |
| CVE-2021-41679 | CRITICAL | 9.8 | 1.3% | Nov 30, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-41678 | CRITICAL | 9.8 | 1.3% | Nov 30, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-25987 | MEDIUM | 4.6 | 0.3% | Nov 30, 2021 | Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious java... |
| CVE-2021-41677 | CRITICAL | 9.8 | 1.3% | Nov 30, 2021 | A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database... |
| CVE-2021-43771 | HIGH | 7.8 | 0.3% | Nov 30, 2021 | Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulne... |
| CVE-2021-42545 | CRITICAL | 9.1 | 1.1% | Nov 30, 2021 | An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.... |
| CVE-2021-42544 | CRITICAL | 9.8 | 1.4% | Nov 30, 2021 | Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27... |
| CVE-2021-42123 | HIGH | 8.8 | 1.0% | Nov 30, 2021 | Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1... |
| CVE-2021-42122 | MEDIUM | 4.3 | 0.7% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42121 | MEDIUM | 4.3 | 1.0% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42120 | MEDIUM | 6.5 | 1.1% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42119 | MEDIUM | 5.4 | 0.5% | Nov 30, 2021 | Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version... |
| CVE-2021-42118 | MEDIUM | 5.4 | 0.7% | Nov 30, 2021 | Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version... |
| CVE-2021-42117 | MEDIUM | 5.4 | 0.7% | Nov 30, 2021 | Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <... |
| CVE-2021-42116 | MEDIUM | 4.3 | 0.8% | Nov 30, 2021 | Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now