2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20845 | HIGH | 8.8 | 0.5% | Nov 24, 2021 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote at... |
| CVE-2021-20844 | MEDIUM | 5.7 | 0.9% | Nov 24, 2021 | Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17... |
| CVE-2021-20843 | MEDIUM | 5.4 | 0.7% | Nov 24, 2021 | Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and ear... |
| CVE-2021-20842 | MEDIUM | 6.5 | 0.5% | Nov 24, 2021 | Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack ... |
| CVE-2021-20841 | MEDIUM | 6.5 | 1.3% | Nov 24, 2021 | Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker... |
| CVE-2021-20840 | MEDIUM | 6.1 | 1.2% | Nov 24, 2021 | Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 all... |
| CVE-2021-20835 | HIGH | 7.5 | 1.3% | Nov 24, 2021 | Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and... |
| CVE-2021-44140 | CRITICAL | 9.1 | 6.2% | Nov 24, 2021 | Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a... |
| CVE-2021-40369 | MEDIUM | 6.1 | 3.3% | Nov 24, 2021 | A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce... |
| CVE-2021-28709 | HIGH | 7.8 | 0.3% | Nov 24, 2021 | issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text expl... |
| CVE-2021-28705 | HIGH | 7.8 | 0.3% | Nov 24, 2021 | issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text expl... |
| CVE-2021-43221 | MEDIUM | 4.2 | 1.0% | Nov 24, 2021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2021-43220 | LOW | 3.1 | 1.1% | Nov 24, 2021 | Microsoft Edge for iOS Spoofing Vulnerability |
| CVE-2021-43211 | MEDIUM | 5.5 | 0.7% | Nov 24, 2021 | Windows 10 Update Assistant Elevation of Privilege Vulnerability |
| CVE-2021-42308 | LOW | 3.1 | 1.1% | Nov 24, 2021 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2021-42306 | HIGH | 8.1 | 3.1% | Nov 24, 2021 | An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as ... |
| CVE-2021-42297 | MEDIUM | 5 | 1.5% | Nov 24, 2021 | Windows 10 Update Assistant Elevation of Privilege Vulnerability |
| CVE-2021-28708 | HIGH | 8.8 | 0.3% | Nov 24, 2021 | PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects... |
| CVE-2021-28707 | HIGH | 8.8 | 0.3% | Nov 24, 2021 | PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects... |
| CVE-2021-28706 | HIGH | 8.6 | 2.1% | Nov 24, 2021 | guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be ab... |
| CVE-2021-28704 | HIGH | 8.8 | 0.3% | Nov 24, 2021 | PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects... |
| CVE-2021-42785 | CRITICAL | 9.8 | 2.3% | Nov 23, 2021 | Buffer Overflow vulnerability in tvnviewer.exe of TightVNC Viewer allows a remote attacker to execute arbitrary instruct... |
| CVE-2021-42784 | CRITICAL | 9.8 | 7.1% | Nov 23, 2021 | OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform comm... |
| CVE-2021-42783 | CRITICAL | 9.8 | 3.8% | Nov 23, 2021 | Missing Authentication for Critical Function vulnerability in debug_post_set.cgi of D-Link DWR-932C E1 firmware allows a... |
| CVE-2021-38004 | MEDIUM | 4.3 | 0.8% | Nov 23, 2021 | Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cro... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now