2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24412 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters fro... |
| CVE-2021-38442 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38440 | LOW | 3.3 | 0.6% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior is vulnerable to an out-of-bounds read, which may allow an attacke... |
| CVE-2021-38438 | HIGH | 7.8 | 1.0% | Oct 18, 2021 | A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid us... |
| CVE-2021-38436 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38434 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38430 | HIGH | 7.8 | 1.0% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files... |
| CVE-2021-38426 | HIGH | 7.8 | 0.9% | Oct 18, 2021 | FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project... |
| CVE-2021-38389 | CRITICAL | 9.8 | 10.4% | Oct 18, 2021 | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker... |
| CVE-2021-33023 | CRITICAL | 9.8 | 2.2% | Oct 18, 2021 | Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker ... |
| CVE-2021-22961 | CRITICAL | 9.8 | 1.7% | Oct 18, 2021 | A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary co... |
| CVE-2021-22942 | MEDIUM | 6.1 | 1.6% | Oct 18, 2021 | A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow att... |
| CVE-2021-21797 | HIGH | 7.8 | 15.0% | Oct 18, 2021 | An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted d... |
| CVE-2021-21796 | HIGH | 7.8 | 15.8% | Oct 18, 2021 | An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafte... |
| CVE-2021-41611 | HIGH | 7.5 | 2.9% | Oct 18, 2021 | An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, S... |
| CVE-2021-38562 | HIGH | 7.5 | 1.7% | Oct 18, 2021 | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive informati... |
| CVE-2021-42566 | MEDIUM | 6.1 | 5.8% | Oct 18, 2021 | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. |
| CVE-2021-42565 | MEDIUM | 6.1 | 5.8% | Oct 18, 2021 | myfactory.FMS before 7.1-912 allows XSS via the UID parameter. |
| CVE-2021-36097 | MEDIUM | 4.3 | 0.5% | Oct 18, 2021 | Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the q... |
| CVE-2021-38297 | CRITICAL | 9.8 | 10.3% | Oct 18, 2021 | Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM... |
| CVE-2021-27561 | CRITICAL | 9.8 | 82.5% | Oct 15, 2021 | Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, ... |
| CVE-2021-41320 | MEDIUM | 5.5 | 0.2% | Oct 15, 2021 | A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than th... |
| CVE-2021-29745 | HIGH | 8.8 | 1.0% | Oct 15, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access ... |
| CVE-2021-29679 | HIGH | 8.8 | 1.9% | Oct 15, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neu... |
| CVE-2021-28021 | HIGH | 7.8 | 1.3% | Oct 15, 2021 | Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now