2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41163 | CRITICAL | 9.8 | 19.8% | Oct 20, 2021 | Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l... |
| CVE-2021-42299 | MEDIUM | 5.6 | 0.7% | Oct 20, 2021 | Microsoft Surface Pro 3 Security Feature Bypass Vulnerability |
| CVE-2021-42771 | HIGH | 7.8 | 0.7% | Oct 20, 2021 | Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python ob... |
| CVE-2021-42766 | CRITICAL | 9.1 | 0.9% | Oct 20, 2021 | The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service... |
| CVE-2021-42765 | HIGH | 7.5 | 0.9% | Oct 20, 2021 | The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to leverage network delay to... |
| CVE-2021-42764 | CRITICAL | 9.1 | 0.9% | Oct 20, 2021 | The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service... |
| CVE-2021-42762 | MEDIUM | 5.3 | 0.5% | Oct 20, 2021 | BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed... |
| CVE-2021-41167 | HIGH | 7.5 | 1.6% | Oct 20, 2021 | modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In... |
| CVE-2021-38896 | MEDIUM | 6.1 | 0.6% | Oct 20, 2021 | IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2021-41135 | MEDIUM | 6.5 | 1.7% | Oct 20, 2021 | The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerab... |
| CVE-2021-21749 | CRITICAL | 9.8 | 1.6% | Oct 20, 2021 | ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to... |
| CVE-2021-21748 | CRITICAL | 9.8 | 1.7% | Oct 20, 2021 | ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to... |
| CVE-2021-21745 | MEDIUM | 4.3 | 55.7% | Oct 20, 2021 | ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use th... |
| CVE-2021-21744 | HIGH | 7.5 | 0.8% | Oct 20, 2021 | ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify th... |
| CVE-2021-21743 | MEDIUM | 4.3 | 0.8% | Oct 20, 2021 | ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP re... |
| CVE-2021-3542 | — | — | — | Oct 20, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42739. Reason: This candidate is a reservation d... |
| CVE-2021-21747 | MEDIUM | 6.1 | 0.6% | Oct 20, 2021 | ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio... |
| CVE-2021-21746 | MEDIUM | 6.1 | 0.6% | Oct 20, 2021 | ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio... |
| CVE-2021-23452 | CRITICAL | 9.8 | 1.5% | Oct 20, 2021 | This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object. |
| CVE-2021-25972 | MEDIUM | 4.9 | 1.0% | Oct 20, 2021 | In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload fea... |
| CVE-2021-25971 | MEDIUM | 4.3 | 1.0% | Oct 20, 2021 | In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes... |
| CVE-2021-25970 | HIGH | 8.8 | 1.3% | Oct 20, 2021 | Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s p... |
| CVE-2021-25969 | MEDIUM | 6.1 | 0.8% | Oct 20, 2021 | In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attack... |
| CVE-2021-35666 | MEDIUM | 5.9 | 1.2% | Oct 20, 2021 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported vers... |
| CVE-2021-35665 | MEDIUM | 6.1 | 0.8% | Oct 20, 2021 | Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported vers... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now