2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26322 | HIGH | 7.5 | 1.0% | Nov 16, 2021 | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. |
| CVE-2021-26312 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ... |
| CVE-2021-38949 | MEDIUM | 5.5 | 0.2% | Nov 16, 2021 | IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local u... |
| CVE-2021-38882 | MEDIUM | 4.4 | 0.2% | Nov 16, 2021 | IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records befo... |
| CVE-2021-43362 | CRITICAL | 9.8 | 0.6% | Nov 16, 2021 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow... |
| CVE-2021-43361 | CRITICAL | 9.8 | 0.6% | Nov 16, 2021 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow... |
| CVE-2021-3958 | CRITICAL | 9.8 | 14.5% | Nov 16, 2021 | Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Inject... |
| CVE-2021-30216 | — | — | — | Nov 16, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-42114 | HIGH | 8.3 | 2.9% | Nov 16, 2021 | Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitiga... |
| CVE-2021-37580 | CRITICAL | 9.8 | 40.1% | Nov 16, 2021 | A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass a... |
| CVE-2021-25985 | CRITICAL | 9.8 | 0.8% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a user’s session even after the user l... |
| CVE-2021-25984 | MEDIUM | 6.1 | 0.7% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site S... |
| CVE-2021-25983 | MEDIUM | 6.1 | 0.7% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Sit... |
| CVE-2021-25982 | MEDIUM | 6.1 | 0.7% | Nov 16, 2021 | In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site ... |
| CVE-2021-25965 | HIGH | 8.8 | 0.5% | Nov 16, 2021 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated... |
| CVE-2021-25940 | HIGH | 8 | 0.8% | Nov 16, 2021 | In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is... |
| CVE-2021-25976 | HIGH | 8.1 | 0.4% | Nov 16, 2021 | In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing variou... |
| CVE-2021-42337 | MEDIUM | 4.3 | 0.9% | Nov 16, 2021 | The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general us... |
| CVE-2021-41271 | MEDIUM | 5.3 | 0.9% | Nov 15, 2021 | Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro... |
| CVE-2021-42386 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42385 | HIGH | 7.2 | 2.7% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42384 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42383 | HIGH | 7.2 | 2.1% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42382 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42381 | HIGH | 7.2 | 2.7% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now