2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23663 | CRITICAL | 9.8 | 1.2% | Dec 10, 2021 | All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function. |
| CVE-2021-23639 | CRITICAL | 9.8 | 5.3% | Dec 10, 2021 | The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matte... |
| CVE-2021-23561 | CRITICAL | 9.8 | 1.2% | Dec 10, 2021 | All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function. |
| CVE-2021-23463 | CRITICAL | 9.1 | 3.3% | Dec 10, 2021 | The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via ... |
| CVE-2021-27983 | CRITICAL | 9.8 | 3.5% | Dec 10, 2021 | Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page. |
| CVE-2021-38917 | CRITICAL | 9.1 | 1.5% | Dec 10, 2021 | IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and... |
| CVE-2021-31746 | CRITICAL | 9.8 | 2.4% | Dec 10, 2021 | Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in ... |
| CVE-2021-37934 | CRITICAL | 9.8 | 1.5% | Dec 10, 2021 | Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterpris... |
| CVE-2021-35978 | CRITICAL | 9.8 | 3.6% | Dec 10, 2021 | An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command exe... |
| CVE-2021-44228 | CRITICAL | 10 | 100.0% | Dec 10, 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in con... |
| CVE-2021-44514 | CRITICAL | 9.8 | 5.4% | Dec 9, 2021 | OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. |
| CVE-2021-43608 | CRITICAL | 9.8 | 2.4% | Dec 9, 2021 | Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIM... |
| CVE-2021-43703 | CRITICAL | 9.8 | 1.8% | Dec 9, 2021 | An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling Java... |
| CVE-2021-41695 | CRITICAL | 9.8 | 1.2% | Dec 9, 2021 | An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. . |
| CVE-2021-41694 | CRITICAL | 9.8 | 1.3% | Dec 9, 2021 | An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in req... |
| CVE-2021-21954 | CRITICAL | 9.9 | 2.4% | Dec 9, 2021 | A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of An... |
| CVE-2021-20146 | CRITICAL | 9.8 | 2.0% | Dec 9, 2021 | An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affi... |
| CVE-2021-3817 | CRITICAL | 9.8 | 37.8% | Dec 9, 2021 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command |
| CVE-2021-4048 | CRITICAL | 9.1 | 2.6% | Dec 8, 2021 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.... |
| CVE-2021-44529 | CRITICAL | 9.8 | 99.1% | Dec 8, 2021 | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut... |
| CVE-2021-43527 | CRITICAL | 9.8 | 17.6% | Dec 8, 2021 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER... |
| CVE-2021-38503 | CRITICAL | 10 | 3.8% | Dec 8, 2021 | The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such ... |
| CVE-2021-21951 | CRITICAL | 10 | 2.4% | Dec 8, 2021 | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security... |
| CVE-2021-21950 | CRITICAL | 10 | 2.4% | Dec 8, 2021 | An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security... |
| CVE-2021-41025 | CRITICAL | 9.8 | 1.4% | Dec 8, 2021 | Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.1... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now