2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43272 | CRITICAL | 9.8 | 3.5% | Nov 14, 2021 | An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 202... |
| CVE-2021-41057 | HIGH | 7.1 | 0.3% | Nov 14, 2021 | In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file withou... |
| CVE-2021-26795 | HIGH | 8.8 | 1.5% | Nov 14, 2021 | A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 ... |
| CVE-2021-43617 | CRITICAL | 9.8 | 19.8% | Nov 14, 2021 | Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val... |
| CVE-2021-43616 | CRITICAL | 9.8 | 2.5% | Nov 13, 2021 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack... |
| CVE-2021-41653 | CRITICAL | 9.8 | 77.5% | Nov 13, 2021 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r... |
| CVE-2021-3915 | MEDIUM | 5.7 | 0.9% | Nov 13, 2021 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-3776 | MEDIUM | 5.4 | 0.4% | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3775 | MEDIUM | 5.4 | 0.4% | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3683 | MEDIUM | 6.5 | 0.4% | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3945 | MEDIUM | 6.1 | 1.0% | Nov 13, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3938 | MEDIUM | 5.4 | 0.5% | Nov 13, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3932 | MEDIUM | 4.3 | 0.4% | Nov 13, 2021 | twill is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3931 | MEDIUM | 4.3 | 0.4% | Nov 13, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3921 | MEDIUM | 4.3 | 0.4% | Nov 13, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3918 | CRITICAL | 9.8 | 3.6% | Nov 13, 2021 | json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-38684 | CRITICAL | 9.8 | 1.3% | Nov 13, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, thi... |
| CVE-2021-34357 | MEDIUM | 6.1 | 0.7% | Nov 13, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, thi... |
| CVE-2021-41229 | MEDIUM | 6.5 | 1.1% | Nov 12, 2021 | BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which... |
| CVE-2021-36325 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-36324 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-36323 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-36315 | MEDIUM | 6.8 | 0.2% | Nov 12, 2021 | Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privil... |
| CVE-2021-36305 | MEDIUM | 6.5 | 0.8% | Nov 12, 2021 | Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An... |
| CVE-2021-21528 | HIGH | 7.5 | 1.0% | Nov 12, 2021 | Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now