2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41715 | HIGH | 8.8 | 1.0% | Apr 8, 2022 | libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. |
| CVE-2021-46367 | HIGH | 7.2 | 29.7% | Apr 8, 2022 | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated ... |
| CVE-2021-46436 | HIGH | 7.2 | 1.0% | Apr 8, 2022 | An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php. |
| CVE-2021-36202 | HIGH | 8.8 | 0.8% | Apr 7, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to in... |
| CVE-2021-43430 | HIGH | 8.8 | 1.1% | Apr 7, 2022 | An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a mal... |
| CVE-2021-43429 | HIGH | 7.5 | 0.9% | Apr 7, 2022 | A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a fail... |
| CVE-2021-46418 | HIGH | 7.5 | 23.9% | Apr 7, 2022 | An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts. |
| CVE-2021-46417 | HIGH | 7.5 | 59.8% | Apr 7, 2022 | Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege... |
| CVE-2021-46416 | HIGH | 8.1 | 6.7% | Apr 7, 2022 | Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce... |
| CVE-2021-43138 | HIGH | 7.8 | 3.3% | Apr 6, 2022 | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/i... |
| CVE-2021-26116 | HIGH | 8.8 | 0.6% | Apr 6, 2022 | An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of Fo... |
| CVE-2021-26113 | HIGH | 7.5 | 0.4% | Apr 6, 2022 | A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker w... |
| CVE-2021-26104 | HIGH | 7.8 | 3.2% | Apr 6, 2022 | Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.... |
| CVE-2021-22127 | HIGH | 8 | 0.5% | Apr 6, 2022 | An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x befo... |
| CVE-2021-44169 | HIGH | 8.8 | 0.4% | Apr 6, 2022 | A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6... |
| CVE-2021-24009 | HIGH | 8.8 | 1.5% | Apr 6, 2022 | Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of Fo... |
| CVE-2021-45104 | HIGH | 7.4 | 0.6% | Apr 6, 2022 | An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor net... |
| CVE-2021-30497 | HIGH | 7.5 | 96.6% | Apr 6, 2022 | Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal... |
| CVE-2021-45103 | HIGH | 8.1 | 0.9% | Apr 6, 2022 | An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S... |
| CVE-2021-27117 | HIGH | 7.8 | 0.4% | Apr 5, 2022 | An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch ... |
| CVE-2021-27116 | HIGH | 7.8 | 0.4% | Apr 5, 2022 | An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlin... |
| CVE-2021-41245 | HIGH | 8.1 | 0.7% | Apr 5, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `... |
| CVE-2021-38834 | HIGH | 8.8 | 2.0% | Apr 5, 2022 | easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through ... |
| CVE-2021-39114 | HIGH | 8.8 | 1.7% | Apr 5, 2022 | Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data C... |
| CVE-2021-45893 | HIGH | 7.5 | 1.6% | Apr 5, 2022 | An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now