2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43140 | CRITICAL | 9.8 | 4.7% | Nov 3, 2021 | SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. |
| CVE-2021-23820 | CRITICAL | 9.8 | 1.8% | Nov 3, 2021 | This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 ... |
| CVE-2021-23807 | CRITICAL | 9.8 | 2.6% | Nov 3, 2021 | This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Pro... |
| CVE-2021-23624 | CRITICAL | 9.8 | 1.2% | Nov 3, 2021 | This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when ... |
| CVE-2021-23509 | CRITICAL | 9.8 | 1.8% | Nov 3, 2021 | This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 whe... |
| CVE-2021-43082 | CRITICAL | 9.8 | 2.3% | Nov 3, 2021 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Ap... |
| CVE-2021-43130 | CRITICAL | 9.8 | 2.2% | Nov 3, 2021 | An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the userna... |
| CVE-2021-40849 | CRITICAL | 9.8 | 1.3% | Nov 3, 2021 | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable ... |
| CVE-2021-39238 | CRITICAL | 9.8 | 12.1% | Nov 3, 2021 | Certain HP Enterprise LaserJet, HP LaserJet Managed, HP Enterprise PageWide, HP PageWide Managed products may be vulnera... |
| CVE-2021-41036 | CRITICAL | 9.8 | 1.2% | Nov 3, 2021 | In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket. |
| CVE-2021-20704 | CRITICAL | 9.8 | 2.1% | Nov 3, 2021 | Buffer overflow vulnerability in the compatible API with previous versions CLUSTERPRO X 4.3 for Windows and earlier, EXP... |
| CVE-2021-20703 | CRITICAL | 9.8 | 2.1% | Nov 3, 2021 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 f... |
| CVE-2021-20702 | CRITICAL | 9.8 | 2.1% | Nov 3, 2021 | Buffer overflow vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 f... |
| CVE-2021-20701 | CRITICAL | 9.8 | 2.1% | Nov 3, 2021 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windo... |
| CVE-2021-20700 | CRITICAL | 9.8 | 2.1% | Nov 3, 2021 | Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windo... |
| CVE-2021-43267 | CRITICAL | 9.8 | 57.9% | Nov 2, 2021 | An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communica... |
| CVE-2021-37981 | CRITICAL | 9.6 | 1.0% | Nov 2, 2021 | Heap buffer overflow in Skia in Google Chrome prior to 95.0.4638.54 allowed a remote attacker who had compromised the re... |
| CVE-2021-36186 | CRITICAL | 9.8 | 1.6% | Nov 2, 2021 | A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attac... |
| CVE-2021-41232 | CRITICAL | 9.8 | 1.5% | Nov 2, 2021 | Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there ... |
| CVE-2021-38948 | CRITICAL | 9.1 | 2.0% | Nov 2, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XM... |
| CVE-2021-36794 | CRITICAL | 9.8 | 1.3% | Nov 2, 2021 | In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications ... |
| CVE-2021-36560 | CRITICAL | 9.8 | 1.5% | Nov 2, 2021 | Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to... |
| CVE-2021-20136 | CRITICAL | 9.8 | 10.5% | Nov 1, 2021 | ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configurati... |
| CVE-2021-26740 | CRITICAL | 9.8 | 1.6% | Nov 1, 2021 | Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code. |
| CVE-2021-26739 | CRITICAL | 9.8 | 1.6% | Nov 1, 2021 | SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attri... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now