2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38283 | HIGH | 7.5 | 2.4% | Nov 29, 2021 | Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing se... |
| CVE-2021-38147 | HIGH | 7.5 | 53.0% | Nov 29, 2021 | Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as report... |
| CVE-2021-21707 | MEDIUM | 5.3 | 26.0% | Nov 29, 2021 | In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simpl... |
| CVE-2021-44077 | CRITICAL | 9.8 | 93.5% | Nov 29, 2021 | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 ... |
| CVE-2021-32061 | MEDIUM | 5.3 | 1.6% | Nov 29, 2021 | S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a Lis... |
| CVE-2021-44094 | HIGH | 7.8 | 1.4% | Nov 28, 2021 | ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file |
| CVE-2021-44093 | CRITICAL | 9.8 | 2.5% | Nov 28, 2021 | A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass t... |
| CVE-2021-4020 | MEDIUM | 5.4 | 0.8% | Nov 27, 2021 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-23654 | CRITICAL | 9.8 | 1.2% | Nov 26, 2021 | This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted with... |
| CVE-2021-43785 | MEDIUM | 6.1 | 1.0% | Nov 26, 2021 | @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for ... |
| CVE-2021-43776 | MEDIUM | 6.1 | 0.7% | Nov 26, 2021 | Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a mali... |
| CVE-2021-41279 | HIGH | 8.8 | 1.6% | Nov 26, 2021 | BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions use... |
| CVE-2021-41243 | HIGH | 8.8 | 2.2% | Nov 26, 2021 | There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS.... |
| CVE-2021-40833 | MEDIUM | 5.5 | 0.4% | Nov 26, 2021 | A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-serv... |
| CVE-2021-36919 | MEDIUM | 5.4 | 0.5% | Nov 26, 2021 | Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (version... |
| CVE-2021-36843 | MEDIUM | 4.8 | 0.6% | Nov 26, 2021 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin ... |
| CVE-2021-35533 | HIGH | 7.5 | 0.9% | Nov 26, 2021 | Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-... |
| CVE-2021-26615 | HIGH | 8.8 | 0.6% | Nov 26, 2021 | ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW functi... |
| CVE-2021-26611 | CRITICAL | 9.8 | 1.1% | Nov 26, 2021 | HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to oper... |
| CVE-2021-36807 | HIGH | 8.8 | 1.5% | Nov 26, 2021 | An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before versi... |
| CVE-2021-25269 | MEDIUM | 4.4 | 0.2% | Nov 26, 2021 | A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service p... |
| CVE-2021-38686 | HIGH | 8.8 | 0.9% | Nov 26, 2021 | An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerabil... |
| CVE-2021-38685 | CRITICAL | 9.8 | 1.5% | Nov 26, 2021 | A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability all... |
| CVE-2021-44225 | MEDIUM | 5.4 | 1.2% | Nov 26, 2021 | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user ... |
| CVE-2021-44223 | CRITICAL | 9.8 | 29.0% | Nov 25, 2021 | WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execut... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now