2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41198 | MEDIUM | 5.5 | 0.2% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions if `tf.tile` is called with a large inp... |
| CVE-2021-41197 | MEDIUM | 5.5 | 0.3% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions TensorFlow allows tensor to have a larg... |
| CVE-2021-41196 | MEDIUM | 5.5 | 0.2% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the Keras pooling layers can trigger a ... |
| CVE-2021-41195 | MEDIUM | 5.5 | 0.2% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the implementation of `tf.math.segment_... |
| CVE-2021-43406 | HIGH | 8.8 | 0.9% | Nov 5, 2021 | An issue was discovered in FusionPBX before 4.5.30. The fax_post_size may have risky characters (it is not constrained t... |
| CVE-2021-43405 | HIGH | 8.8 | 35.6% | Nov 5, 2021 | An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t... |
| CVE-2021-43404 | HIGH | 8.8 | 0.9% | Nov 5, 2021 | An issue was discovered in FusionPBX before 4.5.30. The FAX file name may have risky characters. |
| CVE-2021-42837 | CRITICAL | 9.8 | 1.2% | Nov 5, 2021 | An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not c... |
| CVE-2021-35368 | CRITICAL | 9.8 | 2.5% | Nov 5, 2021 | OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request ... |
| CVE-2021-29753 | MEDIUM | 5.9 | 0.8% | Nov 5, 2021 | IBM Business Automation Workflow 18. 19, 20, 21, and IBM Business Process Manager 8.5 and d8.6 transmits or stores authe... |
| CVE-2021-42701 | MEDIUM | 6.3 | 0.6% | Nov 5, 2021 | An attacker could prepare a specially crafted project file that, if opened, would attempt to connect to the cloud and tr... |
| CVE-2021-42699 | MEDIUM | 5.9 | 0.5% | Nov 5, 2021 | The affected product is vulnerable to cookie information being transmitted as cleartext over HTTP. An attacker can captu... |
| CVE-2021-42698 | HIGH | 7.8 | 0.8% | Nov 5, 2021 | Project files are stored memory objects in the form of binary serialized data that can later be read and deserialized ag... |
| CVE-2021-42543 | HIGH | 7.8 | 0.8% | Nov 5, 2021 | The affected application uses specific functions that could be abused through a crafted project file, which could lead t... |
| CVE-2021-39416 | MEDIUM | 6.1 | 1.1% | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in Remote Clinic v2.0 in (1) patients/register-patient.php vi... |
| CVE-2021-39413 | MEDIUM | 6.1 | 0.8% | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) to_time parameter in (a) backl... |
| CVE-2021-3928 | HIGH | 7.8 | 0.6% | Nov 5, 2021 | vim is vulnerable to Use of Uninitialized Variable |
| CVE-2021-3927 | HIGH | 7.8 | 1.6% | Nov 5, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3924 | HIGH | 7.5 | 4.2% | Nov 5, 2021 | grav is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2021-3916 | MEDIUM | 6.5 | 1.2% | Nov 5, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2021-39412 | MEDIUM | 6.1 | 0.6% | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in PHPGurukul Shopping v3.1 via the (1) callback parameter in... |
| CVE-2021-39411 | MEDIUM | 6.1 | 0.9% | Nov 5, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searc... |
| CVE-2021-42671 | HIGH | 7.5 | 19.7% | Nov 5, 2021 | An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitorin... |
| CVE-2021-42670 | CRITICAL | 9.8 | 8.3% | Nov 5, 2021 | A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announ... |
| CVE-2021-42669 | CRITICAL | 9.8 | 23.3% | Nov 5, 2021 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which all... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now