2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38948 | CRITICAL | 9.1 | 2.0% | Nov 2, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XM... |
| CVE-2021-29888 | HIGH | 8.8 | 0.5% | Nov 2, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec... |
| CVE-2021-29875 | HIGH | 7.5 | 1.1% | Nov 2, 2021 | IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third p... |
| CVE-2021-29771 | MEDIUM | 5.4 | 0.5% | Nov 2, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-29738 | MEDIUM | 5.4 | 0.5% | Nov 2, 2021 | IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery... |
| CVE-2021-29737 | HIGH | 7.5 | 0.7% | Nov 2, 2021 | IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of ... |
| CVE-2021-36794 | CRITICAL | 9.8 | 1.3% | Nov 2, 2021 | In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications ... |
| CVE-2021-42568 | MEDIUM | 4.3 | 0.5% | Nov 2, 2021 | Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function vi... |
| CVE-2021-36925 | HIGH | 7.8 | 0.3% | Nov 2, 2021 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ... |
| CVE-2021-36924 | HIGH | 7.8 | 0.2% | Nov 2, 2021 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ... |
| CVE-2021-36923 | HIGH | 7.8 | 0.3% | Nov 2, 2021 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ... |
| CVE-2021-36922 | HIGH | 7.8 | 0.3% | Nov 2, 2021 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ... |
| CVE-2021-42763 | HIGH | 7.5 | 0.6% | Nov 2, 2021 | Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the ... |
| CVE-2021-37842 | HIGH | 7.5 | 0.6% | Nov 2, 2021 | metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials ca... |
| CVE-2021-27723 | — | — | — | Nov 2, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-27722 | MEDIUM | 5.5 | 1.3% | Nov 2, 2021 | An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data ... |
| CVE-2021-36560 | CRITICAL | 9.8 | 1.5% | Nov 2, 2021 | Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to... |
| CVE-2021-33611 | MEDIUM | 6.1 | 1.0% | Nov 2, 2021 | Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2... |
| CVE-2021-3765 | HIGH | 7.5 | 1.7% | Nov 2, 2021 | validator.js is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-33593 | MEDIUM | 5.3 | 0.7% | Nov 2, 2021 | Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the ad... |
| CVE-2021-25973 | MEDIUM | 6.5 | 0.8% | Nov 2, 2021 | In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even whe... |
| CVE-2021-41310 | MEDIUM | 6.1 | 0.7% | Nov 1, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or ... |
| CVE-2021-43058 | MEDIUM | 6.1 | 0.6% | Nov 1, 2021 | An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exp... |
| CVE-2021-41187 | HIGH | 8.8 | 0.8% | Nov 1, 2021 | DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection s... |
| CVE-2021-39346 | MEDIUM | 4.8 | 0.9% | Nov 1, 2021 | The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now