2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44219 | CRITICAL | 9.8 | 1.3% | Nov 24, 2021 | Gin-Vue-Admin before 2.4.6 mishandles a SQL database. |
| CVE-2021-43778 | HIGH | 7.5 | 52.7% | Nov 24, 2021 | Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the ... |
| CVE-2021-41270 | MEDIUM | 6.5 | 1.4% | Nov 24, 2021 | Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and consol... |
| CVE-2021-41268 | HIGH | 8.8 | 1.3% | Nov 24, 2021 | Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of... |
| CVE-2021-41267 | MEDIUM | 6.5 | 1.2% | Nov 24, 2021 | Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set... |
| CVE-2021-22957 | HIGH | 8.8 | 0.9% | Nov 24, 2021 | A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allow... |
| CVE-2021-43268 | MEDIUM | 6.5 | 0.8% | Nov 24, 2021 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to readin... |
| CVE-2021-38873 | HIGH | 7.8 | 1.8% | Nov 24, 2021 | IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary command... |
| CVE-2021-36917 | HIGH | 7.5 | 1.9% | Nov 24, 2021 | WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie... |
| CVE-2021-36916 | CRITICAL | 9.8 | 1.8% | Nov 24, 2021 | The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP... |
| CVE-2021-34424 | HIGH | 7.5 | 1.7% | Nov 24, 2021 | A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before vers... |
| CVE-2021-34423 | CRITICAL | 9.8 | 3.2% | Nov 24, 2021 | A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)... |
| CVE-2021-22049 | CRITICAL | 9.8 | 1.7% | Nov 24, 2021 | The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client ... |
| CVE-2021-21980 | HIGH | 7.5 | 4.6% | Nov 24, 2021 | The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n... |
| CVE-2021-43780 | HIGH | 8.8 | 1.0% | Nov 24, 2021 | Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading da... |
| CVE-2021-43777 | MEDIUM | 6.1 | 0.3% | Nov 24, 2021 | Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google L... |
| CVE-2021-41192 | MEDIUM | 6.5 | 8.0% | Nov 24, 2021 | Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without exp... |
| CVE-2021-3554 | CRITICAL | 10 | 2.7% | Nov 24, 2021 | Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for... |
| CVE-2021-3553 | HIGH | 7.5 | 1.3% | Nov 24, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows... |
| CVE-2021-3552 | HIGH | 7.5 | 1.4% | Nov 24, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To... |
| CVE-2021-32037 | MEDIUM | 6.5 | 1.2% | Nov 24, 2021 | An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregati... |
| CVE-2021-31822 | HIGH | 7.8 | 0.2% | Nov 24, 2021 | When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. ... |
| CVE-2021-20850 | CRITICAL | 9.8 | 1.5% | Nov 24, 2021 | PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 ... |
| CVE-2021-20848 | MEDIUM | 6.1 | 0.9% | Nov 24, 2021 | Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary scr... |
| CVE-2021-20846 | HIGH | 8.8 | 0.7% | Nov 24, 2021 | Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allow... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now