2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31845 | HIGH | 7.3 | 1.1% | Sep 17, 2021 | A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in th... |
| CVE-2021-31844 | HIGH | 7.3 | 0.4% | Sep 17, 2021 | A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a loc... |
| CVE-2021-31843 | HIGH | 7.8 | 0.3% | Sep 17, 2021 | Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Up... |
| CVE-2021-31842 | MEDIUM | 5.5 | 0.2% | Sep 17, 2021 | XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 202... |
| CVE-2021-39327 | MEDIUM | 5.3 | 72.3% | Sep 17, 2021 | The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur... |
| CVE-2021-23442 | CRITICAL | 9.8 | 1.5% | Sep 17, 2021 | This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object. |
| CVE-2021-41303 | CRITICAL | 9.8 | 75.6% | Sep 17, 2021 | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe... |
| CVE-2021-3812 | MEDIUM | 6.1 | 0.5% | Sep 17, 2021 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3811 | MEDIUM | 6.1 | 0.5% | Sep 17, 2021 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3810 | HIGH | 7.5 | 1.2% | Sep 17, 2021 | code-server is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3807 | HIGH | 7.5 | 3.3% | Sep 17, 2021 | ansi-regex is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3804 | HIGH | 7.5 | 1.2% | Sep 17, 2021 | taro is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-3803 | HIGH | 7.5 | 2.0% | Sep 17, 2021 | nth-check is vulnerable to Inefficient Regular Expression Complexity |
| CVE-2021-30261 | HIGH | 7.8 | 0.2% | Sep 17, 2021 | Possible integer and heap overflow due to lack of input command size validation while handling beacon template update co... |
| CVE-2021-30260 | HIGH | 7.8 | 0.1% | Sep 17, 2021 | Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan... |
| CVE-2021-1976 | CRITICAL | 9.8 | 0.8% | Sep 17, 2021 | A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snap... |
| CVE-2021-1947 | HIGH | 7.8 | 0.2% | Sep 17, 2021 | Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snap... |
| CVE-2021-1939 | MEDIUM | 5.5 | 0.1% | Sep 17, 2021 | Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdrag... |
| CVE-2021-3805 | HIGH | 7.5 | 2.0% | Sep 17, 2021 | object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-20828 | MEDIUM | 6.1 | 0.7% | Sep 17, 2021 | Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a r... |
| CVE-2021-20825 | MEDIUM | 6.1 | 0.7% | Sep 17, 2021 | Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and e... |
| CVE-2021-20791 | CRITICAL | 9.3 | 0.8% | Sep 17, 2021 | Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restr... |
| CVE-2021-20790 | CRITICAL | 9.6 | 1.2% | Sep 17, 2021 | Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execu... |
| CVE-2021-41314 | HIGH | 8.8 | 13.6% | Sep 16, 2021 | Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several fau... |
| CVE-2021-40670 | CRITICAL | 9.8 | 1.2% | Sep 16, 2021 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now