2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27203 | MEDIUM | 5.5 | 0.4% | Feb 16, 2021 | In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitr... |
| CVE-2021-20071 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t... |
| CVE-2021-20070 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t... |
| CVE-2021-20069 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th... |
| CVE-2021-20068 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th... |
| CVE-2021-20067 | MEDIUM | 5.3 | 0.8% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authen... |
| CVE-2021-20066 | MEDIUM | 5.6 | 1.4% | Feb 16, 2021 | JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious we... |
| CVE-2021-27237 | MEDIUM | 4.8 | 1.0% | Feb 16, 2021 | The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/... |
| CVE-2021-21317 | MEDIUM | 5.3 | 2.5% | Feb 16, 2021 | uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In u... |
| CVE-2021-23841 | MEDIUM | 5.9 | 7.5% | Feb 16, 2021 | The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer... |
| CVE-2021-27235 | MEDIUM | 4.9 | 0.8% | Feb 16, 2021 | An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, there is a f... |
| CVE-2021-27233 | MEDIUM | 4.9 | 0.5% | Feb 16, 2021 | An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. On the admin portal of the web application, password inf... |
| CVE-2021-27231 | MEDIUM | 5.4 | 1.4% | Feb 16, 2021 | Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to cr... |
| CVE-2021-25299 | MEDIUM | 6.1 | 97.7% | Feb 15, 2021 | Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/na... |
| CVE-2021-23336 | MEDIUM | 5.9 | 36.0% | Feb 15, 2021 | The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9... |
| CVE-2021-26929 | MEDIUM | 6.1 | 4.9% | Feb 14, 2021 | An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library befor... |
| CVE-2021-27210 | MEDIUM | 6.5 | 0.8% | Feb 13, 2021 | TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,... |
| CVE-2021-22984 | MEDIUM | 6.1 | 0.6% | Feb 12, 2021 | On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x be... |
| CVE-2021-22983 | MEDIUM | 5.4 | 0.5% | Feb 12, 2021 | On BIG-IP AFM version 15.1.x before 15.1.1, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.5, authenticated users acce... |
| CVE-2021-22981 | MEDIUM | 4.8 | 0.5% | Feb 12, 2021 | On all versions of BIG-IP 12.1.x and 11.6.x, the original TLS protocol includes a weakness in the master secret negotiat... |
| CVE-2021-22979 | MEDIUM | 6.1 | 0.6% | Feb 12, 2021 | On BIG-IP version 16.0.x before 16.0.1, 15.1.x before 15.1.1, 14.1.x before 14.1.2.8, 13.1.x before 13.1.3.5, and all 12... |
| CVE-2021-20410 | MEDIUM | 5.3 | 0.6% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an... |
| CVE-2021-20408 | MEDIUM | 5.5 | 0.2% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to... |
| CVE-2021-20406 | MEDIUM | 4.9 | 0.5% | Feb 12, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allo... |
| CVE-2021-27205 | MEDIUM | 5.5 | 0.3% | Feb 12, 2021 | Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leadin... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now