2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43141 | MEDIUM | 6.1 | 1.4% | Nov 3, 2021 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter i... |
| CVE-2021-43140 | CRITICAL | 9.8 | 4.7% | Nov 3, 2021 | SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. |
| CVE-2021-41174 | MEDIUM | 6.1 | 84.6% | Nov 3, 2021 | Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to conv... |
| CVE-2021-41134 | MEDIUM | 5.4 | 0.7% | Nov 3, 2021 | nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (... |
| CVE-2021-23820 | CRITICAL | 9.8 | 1.8% | Nov 3, 2021 | This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 ... |
| CVE-2021-23807 | CRITICAL | 9.8 | 2.6% | Nov 3, 2021 | This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Pro... |
| CVE-2021-23784 | MEDIUM | 6.1 | 1.2% | Nov 3, 2021 | This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is r... |
| CVE-2021-23624 | CRITICAL | 9.8 | 1.2% | Nov 3, 2021 | This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when ... |
| CVE-2021-23509 | CRITICAL | 9.8 | 1.8% | Nov 3, 2021 | This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 whe... |
| CVE-2021-23472 | MEDIUM | 6.1 | 2.3% | Nov 3, 2021 | This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of i... |
| CVE-2021-40985 | MEDIUM | 5.5 | 0.9% | Nov 3, 2021 | A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BM... |
| CVE-2021-27836 | MEDIUM | 6.5 | 1.1% | Nov 3, 2021 | An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial o... |
| CVE-2021-26786 | HIGH | 8.8 | 1.5% | Nov 3, 2021 | An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbit... |
| CVE-2021-43082 | CRITICAL | 9.8 | 2.3% | Nov 3, 2021 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Ap... |
| CVE-2021-41585 | HIGH | 7.5 | 2.4% | Nov 3, 2021 | Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to m... |
| CVE-2021-38161 | HIGH | 8.1 | 1.9% | Nov 3, 2021 | Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle a... |
| CVE-2021-37149 | HIGH | 7.5 | 2.5% | Nov 3, 2021 | Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request... |
| CVE-2021-37148 | HIGH | 7.5 | 2.5% | Nov 3, 2021 | Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request... |
| CVE-2021-37147 | HIGH | 7.5 | 2.4% | Nov 3, 2021 | Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request... |
| CVE-2021-43324 | MEDIUM | 6.1 | 0.6% | Nov 3, 2021 | LibreNMS through 21.10.2 allows XSS via a widget title. |
| CVE-2021-43130 | CRITICAL | 9.8 | 2.2% | Nov 3, 2021 | An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the userna... |
| CVE-2021-36698 | MEDIUM | 5.4 | 0.7% | Nov 3, 2021 | Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name. |
| CVE-2021-36697 | MEDIUM | 6.7 | 0.4% | Nov 3, 2021 | With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component... |
| CVE-2021-40849 | CRITICAL | 9.8 | 1.3% | Nov 3, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable ... |
| CVE-2021-40848 | HIGH | 7.8 | 1.0% | Nov 3, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now