2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39497 | CRITICAL | 9.8 | 2.3% | Sep 7, 2021 | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveR... |
| CVE-2021-39496 | MEDIUM | 5.4 | 0.6% | Sep 7, 2021 | Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to t... |
| CVE-2021-39194 | MEDIUM | 6.5 | 1.6% | Sep 7, 2021 | kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions at... |
| CVE-2021-38707 | MEDIUM | 5.4 | 0.6% | Sep 7, 2021 | Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce a... |
| CVE-2021-38706 | HIGH | 8.8 | 1.0% | Sep 7, 2021 | messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged att... |
| CVE-2021-38705 | HIGH | 8.8 | 0.7% | Sep 7, 2021 | ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticate... |
| CVE-2021-38704 | MEDIUM | 6.1 | 3.5% | Sep 7, 2021 | Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to in... |
| CVE-2021-37631 | MEDIUM | 6.5 | 1.2% | Sep 7, 2021 | Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams inte... |
| CVE-2021-37630 | MEDIUM | 6.5 | 1.2% | Sep 7, 2021 | Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud... |
| CVE-2021-35948 | MEDIUM | 5.4 | 0.7% | Sep 7, 2021 | Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass th... |
| CVE-2021-35946 | CRITICAL | 9.8 | 1.4% | Sep 7, 2021 | A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio... |
| CVE-2021-32782 | MEDIUM | 5.4 | 0.8% | Sep 7, 2021 | Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud... |
| CVE-2021-39199 | MEDIUM | 6.1 | 1.0% | Sep 7, 2021 | remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of ... |
| CVE-2021-39196 | MEDIUM | 6.5 | 1.2% | Sep 7, 2021 | pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticat... |
| CVE-2021-39195 | MEDIUM | 6.5 | 1.0% | Sep 7, 2021 | Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vuln... |
| CVE-2021-35949 | MEDIUM | 5.3 | 0.9% | Sep 7, 2021 | The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upl... |
| CVE-2021-35947 | MEDIUM | 5.3 | 1.2% | Sep 7, 2021 | The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal pa... |
| CVE-2021-39197 | HIGH | 8.8 | 0.6% | Sep 7, 2021 | better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It... |
| CVE-2021-38142 | HIGH | 8.8 | 0.5% | Sep 7, 2021 | Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker o... |
| CVE-2021-40539 | CRITICAL | 9.8 | 99.0% | Sep 7, 2021 | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta... |
| CVE-2021-38123 | MEDIUM | 6.1 | 0.6% | Sep 7, 2021 | Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.... |
| CVE-2021-39263 | HIGH | 7.8 | 0.4% | Sep 7, 2021 | A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_... |
| CVE-2021-39262 | HIGH | 7.8 | 0.4% | Sep 7, 2021 | A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22. |
| CVE-2021-39261 | HIGH | 7.8 | 0.4% | Sep 7, 2021 | A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22. |
| CVE-2021-39260 | HIGH | 7.8 | 0.4% | Sep 7, 2021 | A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now