2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42115 | CRITICAL | 9.1 | 1.2% | Nov 30, 2021 | Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27... |
| CVE-2021-3769 | CRITICAL | 9.8 | 0.9% | Nov 30, 2021 | # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P`... |
| CVE-2021-3727 | CRITICAL | 9.8 | 1.0% | Nov 30, 2021 | # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes fro... |
| CVE-2021-3726 | CRITICAL | 9.8 | 0.8% | Nov 30, 2021 | # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` ... |
| CVE-2021-3725 | HIGH | 8.8 | 1.1% | Nov 30, 2021 | Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered... |
| CVE-2021-43790 | HIGH | 8.1 | 1.6% | Nov 30, 2021 | Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all v... |
| CVE-2021-44429 | HIGH | 7.5 | 1.9% | Nov 29, 2021 | Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod... |
| CVE-2021-44428 | HIGH | 7.5 | 2.9% | Nov 29, 2021 | Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod... |
| CVE-2021-44427 | CRITICAL | 9.8 | 50.6% | Nov 29, 2021 | An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow... |
| CVE-2021-43788 | MEDIUM | 5 | 25.8% | Nov 29, 2021 | Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that... |
| CVE-2021-43787 | MEDIUM | 6.1 | 1.3% | Nov 29, 2021 | Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the u... |
| CVE-2021-43786 | HIGH | 7.5 | 2.3% | Nov 29, 2021 | Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verific... |
| CVE-2021-43783 | HIGH | 8.5 | 1.2% | Nov 29, 2021 | @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a... |
| CVE-2021-34800 | HIGH | 7.5 | 1.0% | Nov 29, 2021 | Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before... |
| CVE-2021-44203 | MEDIUM | 5.4 | 0.5% | Nov 29, 2021 | Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis ... |
| CVE-2021-44202 | MEDIUM | 5.4 | 0.5% | Nov 29, 2021 | Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber P... |
| CVE-2021-44201 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Prot... |
| CVE-2021-44200 | MEDIUM | 5.4 | 0.5% | Nov 29, 2021 | Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect... |
| CVE-2021-44199 | MEDIUM | 5.5 | 0.2% | Nov 29, 2021 | DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) b... |
| CVE-2021-44198 | HIGH | 7.8 | 0.2% | Nov 29, 2021 | DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (W... |
| CVE-2021-42365 | MEDIUM | 4.8 | 0.7% | Nov 29, 2021 | The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the na... |
| CVE-2021-42364 | HIGH | 8.8 | 0.6% | Nov 29, 2021 | The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_pa... |
| CVE-2021-42358 | HIGH | 8.8 | 0.6% | Nov 29, 2021 | The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validati... |
| CVE-2021-43691 | CRITICAL | 9.8 | 1.5% | Nov 29, 2021 | tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The varia... |
| CVE-2021-3802 | MEDIUM | 4.2 | 0.8% | Nov 29, 2021 | A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to ke... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now