2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38466 | MEDIUM | 6.1 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client... |
| CVE-2021-38464 | HIGH | 7.4 | 0.3% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow... |
| CVE-2021-38462 | CRITICAL | 9.8 | 1.1% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This ... |
| CVE-2021-42261 | HIGH | 7.5 | 2.2% | Oct 19, 2021 | Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation coul... |
| CVE-2021-36512 | HIGH | 7.5 | 0.9% | Oct 19, 2021 | An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers t... |
| CVE-2021-25968 | MEDIUM | 5.4 | 0.5% | Oct 19, 2021 | In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged applicatio... |
| CVE-2021-20836 | MEDIUM | 6.5 | 0.8% | Oct 19, 2021 | Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privile... |
| CVE-2021-41155 | HIGH | 8.8 | 1.5% | Oct 18, 2021 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi... |
| CVE-2021-41154 | HIGH | 8.8 | 1.5% | Oct 18, 2021 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi... |
| CVE-2021-42650 | MEDIUM | 6.1 | 0.6% | Oct 18, 2021 | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates. |
| CVE-2021-41156 | MEDIUM | 5.4 | 0.5% | Oct 18, 2021 | anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden c... |
| CVE-2021-41153 | CRITICAL | 9.8 | 1.0% | Oct 18, 2021 | The evm crate is a pure Rust implementation of Ethereum Virtual Machine. In `evm` crate `< 0.31.0`, `JUMPI` opcode's con... |
| CVE-2021-41152 | HIGH | 7.7 | 1.2% | Oct 18, 2021 | OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning man... |
| CVE-2021-41151 | MEDIUM | 4.9 | 1.3% | Oct 18, 2021 | Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitiv... |
| CVE-2021-42055 | MEDIUM | 6.8 | 0.2% | Oct 18, 2021 | ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically... |
| CVE-2021-36513 | HIGH | 7.5 | 1.8% | Oct 18, 2021 | An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may all... |
| CVE-2021-29878 | MEDIUM | 5.4 | 0.5% | Oct 18, 2021 | IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2021-23449 | CRITICAL | 10 | 3.5% | Oct 18, 2021 | This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitr... |
| CVE-2021-42576 | CRITICAL | 9.8 | 1.5% | Oct 18, 2021 | The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce ... |
| CVE-2021-42575 | CRITICAL | 9.8 | 2.8% | Oct 18, 2021 | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, an... |
| CVE-2021-41971 | HIGH | 8.8 | 1.7% | Oct 18, 2021 | Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allow... |
| CVE-2021-32609 | MEDIUM | 5.4 | 1.6% | Oct 18, 2021 | Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker ... |
| CVE-2021-42098 | HIGH | 8.8 | 1.6% | Oct 18, 2021 | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to byp... |
| CVE-2021-41991 | HIGH | 7.5 | 4.8% | Oct 18, 2021 | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests wi... |
| CVE-2021-41990 | HIGH | 7.5 | 6.4% | Oct 18, 2021 | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS sig... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now