2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36306 | CRITICAL | 9.8 | 3.6% | Nov 20, 2021 | Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerabili... |
| CVE-2021-38681 | MEDIUM | 5.4 | 0.7% | Nov 20, 2021 | A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exp... |
| CVE-2021-34358 | HIGH | 8.8 | 0.4% | Nov 20, 2021 | We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and la... |
| CVE-2021-39198 | MEDIUM | 5.4 | 0.3% | Nov 19, 2021 | OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a v... |
| CVE-2021-41280 | CRITICAL | 9.8 | 3.4% | Nov 19, 2021 | Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is pos... |
| CVE-2021-23433 | CRITICAL | 9.8 | 1.6% | Nov 19, 2021 | The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in ... |
| CVE-2021-21898 | HIGH | 8.8 | 2.5% | Nov 19, 2021 | A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-... |
| CVE-2021-44038 | HIGH | 7.8 | 0.8% | Nov 19, 2021 | An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (w... |
| CVE-2021-43555 | HIGH | 7.8 | 38.0% | Nov 19, 2021 | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may ... |
| CVE-2021-42744 | MEDIUM | 5.5 | 0.3% | Nov 19, 2021 | Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr... |
| CVE-2021-42254 | HIGH | 7.8 | 0.3% | Nov 19, 2021 | BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions... |
| CVE-2021-40391 | CRITICAL | 9.8 | 2.9% | Nov 19, 2021 | An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (co... |
| CVE-2021-36884 | MEDIUM | 5.4 | 0.6% | Nov 19, 2021 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1... |
| CVE-2021-26262 | MEDIUM | 5.5 | 0.6% | Nov 19, 2021 | Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr... |
| CVE-2021-26248 | MEDIUM | 5.5 | 0.2% | Nov 19, 2021 | Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr... |
| CVE-2021-22970 | HIGH | 7.5 | 1.4% | Nov 19, 2021 | Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system... |
| CVE-2021-22969 | MEDIUM | 5.3 | 0.8% | Nov 19, 2021 | Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an at... |
| CVE-2021-22968 | HIGH | 7.2 | 3.1% | Nov 19, 2021 | A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Co... |
| CVE-2021-22967 | HIGH | 7.5 | 1.1% | Nov 19, 2021 | In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowe... |
| CVE-2021-22966 | HIGH | 8.8 | 0.9% | Nov 19, 2021 | Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "... |
| CVE-2021-22965 | HIGH | 7.5 | 2.1% | Nov 19, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial ... |
| CVE-2021-22951 | HIGH | 7.5 | 1.1% | Nov 19, 2021 | Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) p... |
| CVE-2021-21900 | HIGH | 8.8 | 2.5% | Nov 19, 2021 | A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f... |
| CVE-2021-21899 | HIGH | 8.8 | 2.7% | Nov 19, 2021 | A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2... |
| CVE-2021-41569 | HIGH | 7.5 | 7.8% | Nov 19, 2021 | SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now