2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42380 | HIGH | 7.2 | 2.9% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42379 | HIGH | 7.2 | 2.7% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42378 | HIGH | 7.2 | 2.6% | Nov 15, 2021 | A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte... |
| CVE-2021-42377 | CRITICAL | 9.8 | 3.4% | Nov 15, 2021 | An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when... |
| CVE-2021-42376 | MEDIUM | 5.5 | 0.4% | Nov 15, 2021 | A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, ... |
| CVE-2021-42375 | MEDIUM | 5.5 | 0.4% | Nov 15, 2021 | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted ... |
| CVE-2021-42374 | MEDIUM | 5.3 | 0.6% | Nov 15, 2021 | An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-... |
| CVE-2021-42373 | MEDIUM | 5.5 | 0.4% | Nov 15, 2021 | A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no pag... |
| CVE-2021-41269 | CRITICAL | 9.8 | 4.0% | Nov 15, 2021 | cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for th... |
| CVE-2021-41266 | CRITICAL | 9.8 | 51.4% | Nov 15, 2021 | Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage pro... |
| CVE-2021-41263 | HIGH | 8.8 | 0.6% | Nov 15, 2021 | rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Ra... |
| CVE-2021-41244 | HIGH | 7.2 | 2.8% | Nov 15, 2021 | Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access c... |
| CVE-2021-39222 | MEDIUM | 6.1 | 1.1% | Nov 15, 2021 | Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a store... |
| CVE-2021-42580 | CRITICAL | 9.8 | 10.0% | Nov 15, 2021 | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm... |
| CVE-2021-41951 | MEDIUM | 6.1 | 77.9% | Nov 15, 2021 | ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_ss... |
| CVE-2021-41950 | CRITICAL | 9.1 | 74.9% | Nov 15, 2021 | A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete ... |
| CVE-2021-41765 | CRITICAL | 9.8 | 67.8% | Nov 15, 2021 | A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote... |
| CVE-2021-38984 | HIGH | 7.5 | 0.6% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could ... |
| CVE-2021-38983 | HIGH | 7.5 | 0.9% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could ... |
| CVE-2021-38982 | MEDIUM | 5.4 | 0.5% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2021-38981 | MEDIUM | 5.3 | 1.3% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information ... |
| CVE-2021-38979 | HIGH | 7.5 | 0.7% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should... |
| CVE-2021-38978 | MEDIUM | 5.9 | 0.9% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information,... |
| CVE-2021-38977 | MEDIUM | 4.3 | 0.5% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or s... |
| CVE-2021-38976 | MEDIUM | 5.5 | 0.2% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now