2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41188 | MEDIUM | 5.4 | 0.7% | Oct 26, 2021 | Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This ... |
| CVE-2021-41185 | MEDIUM | 6.5 | 1.4% | Oct 26, 2021 | Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with a... |
| CVE-2021-41184 | MEDIUM | 6.1 | 42.8% | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option... |
| CVE-2021-41183 | MEDIUM | 6.1 | 7.9% | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`... |
| CVE-2021-41182 | MEDIUM | 6.1 | 37.8% | Oct 26, 2021 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` ... |
| CVE-2021-41175 | MEDIUM | 5.4 | 0.9% | Oct 26, 2021 | Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistic... |
| CVE-2021-41173 | MEDIUM | 5.7 | 1.2% | Oct 26, 2021 | Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node i... |
| CVE-2021-41172 | MEDIUM | 5.4 | 1.0% | Oct 26, 2021 | AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Sel... |
| CVE-2021-41158 | HIGH | 7.5 | 0.8% | Oct 26, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-41157 | MEDIUM | 5.3 | 1.7% | Oct 26, 2021 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2021-37364 | HIGH | 7.8 | 1.3% | Oct 26, 2021 | OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify perm... |
| CVE-2021-37363 | HIGH | 7.8 | 1.6% | Oct 26, 2021 | An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.e... |
| CVE-2021-41078 | HIGH | 7.8 | 1.5% | Oct 26, 2021 | Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file. |
| CVE-2021-37372 | HIGH | 8.8 | 3.3% | Oct 26, 2021 | Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can uplo... |
| CVE-2021-37371 | CRITICAL | 9.8 | 2.1% | Oct 26, 2021 | Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login... |
| CVE-2021-26609 | HIGH | 7.5 | 1.7% | Oct 26, 2021 | A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type paramete... |
| CVE-2021-26607 | CRITICAL | 9.8 | 1.8% | Oct 26, 2021 | An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary com... |
| CVE-2021-41873 | CRITICAL | 10 | 0.9% | Oct 26, 2021 | Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unau... |
| CVE-2021-42343 | CRITICAL | 9.8 | 2.9% | Oct 26, 2021 | An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters starte... |
| CVE-2021-40345 | HIGH | 7.2 | 23.0% | Oct 26, 2021 | An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can uplo... |
| CVE-2021-40344 | HIGH | 7.2 | 66.2% | Oct 26, 2021 | An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can uplo... |
| CVE-2021-40343 | HIGH | 7.8 | 0.7% | Oct 26, 2021 | An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios u... |
| CVE-2021-34596 | MEDIUM | 6.5 | 0.8% | Oct 26, 2021 | A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCW... |
| CVE-2021-34595 | HIGH | 8.1 | 0.9% | Oct 26, 2021 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 ... |
| CVE-2021-34593 | HIGH | 7.5 | 2.6% | Oct 26, 2021 | In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid reque... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now