2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29735 | MEDIUM | 5.4 | 0.5% | Nov 8, 2021 | IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability a... |
| CVE-2021-42770 | MEDIUM | 6.1 | 1.3% | Nov 8, 2021 | A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the... |
| CVE-2021-41733 | MEDIUM | 6.1 | 0.7% | Nov 8, 2021 | Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. |
| CVE-2021-39182 | HIGH | 7.5 | 0.5% | Nov 8, 2021 | EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorith... |
| CVE-2021-28024 | CRITICAL | 9.8 | 1.3% | Nov 8, 2021 | Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to lo... |
| CVE-2021-28023 | CRITICAL | 9.8 | 1.3% | Nov 8, 2021 | Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious... |
| CVE-2021-28022 | HIGH | 7.5 | 1.1% | Nov 8, 2021 | Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate inform... |
| CVE-2021-25979 | CRITICAL | 9.8 | 1.1% | Nov 8, 2021 | Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or chang... |
| CVE-2021-37850 | MEDIUM | 5.5 | 0.2% | Nov 8, 2021 | ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to ... |
| CVE-2021-32483 | MEDIUM | 5.3 | 0.8% | Nov 8, 2021 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. |
| CVE-2021-30132 | CRITICAL | 9.8 | 1.1% | Nov 8, 2021 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges. |
| CVE-2021-22051 | MEDIUM | 6.5 | 0.7% | Nov 8, 2021 | Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request... |
| CVE-2021-32482 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. |
| CVE-2021-32481 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Cloudera Hue 4.6.0 allows XSS via the type parameter. |
| CVE-2021-29994 | MEDIUM | 6.1 | 0.9% | Nov 8, 2021 | Cloudera Hue 4.6.0 allows XSS. |
| CVE-2021-29243 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. |
| CVE-2021-41772 | HIGH | 7.5 | 3.1% | Nov 8, 2021 | Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing ... |
| CVE-2021-41771 | HIGH | 7.5 | 4.4% | Nov 8, 2021 | ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Loc... |
| CVE-2021-42372 | HIGH | 8.8 | 6.1% | Nov 8, 2021 | A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticate... |
| CVE-2021-42371 | CRITICAL | 9.8 | 1.5% | Nov 8, 2021 | lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30. |
| CVE-2021-42370 | HIGH | 7.5 | 0.7% | Nov 8, 2021 | A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is pr... |
| CVE-2021-42078 | MEDIUM | 6.1 | 0.9% | Nov 8, 2021 | PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/... |
| CVE-2021-42077 | CRITICAL | 9.8 | 2.4% | Nov 8, 2021 | PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username... |
| CVE-2021-42076 | HIGH | 7.5 | 1.5% | Nov 8, 2021 | An issue was discovered in Barrier before 2.3.4. An attacker can cause memory exhaustion in the barriers component (aka ... |
| CVE-2021-42075 | HIGH | 7.5 | 2.1% | Nov 8, 2021 | An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now