2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22246 | MEDIUM | 6.5 | 1.3% | Aug 20, 2021 | A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abuse... |
| CVE-2021-22238 | MEDIUM | 5.4 | 71.8% | Aug 20, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS ... |
| CVE-2021-21823 | HIGH | 7.5 | 0.9% | Aug 20, 2021 | An information disclosure vulnerability exists in the Friend finder functionality of GmbH Komoot version 10.26.9 up to 1... |
| CVE-2021-34433 | HIGH | 7.5 | 0.3% | Aug 20, 2021 | In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handsh... |
| CVE-2021-34228 | MEDIUM | 6.1 | 29.2% | Aug 20, 2021 | Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows... |
| CVE-2021-34223 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in urlfilter.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows atta... |
| CVE-2021-34220 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in tr069config.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows at... |
| CVE-2021-34218 | MEDIUM | 5.3 | 0.8% | Aug 20, 2021 | Directory Indexing in Login Portal of Login Portal of TOTOLINK-A702R-V1.0.0-B20161227.1023 allows attacker to access /ad... |
| CVE-2021-34215 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in tcpipwan.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attac... |
| CVE-2021-34207 | MEDIUM | 6.1 | 0.7% | Aug 20, 2021 | Cross-site scripting in ddns.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows attackers... |
| CVE-2021-37598 | MEDIUM | 5.3 | 2.4% | Aug 19, 2021 | WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character. |
| CVE-2021-37597 | CRITICAL | 9.8 | 2.1% | Aug 19, 2021 | WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. |
| CVE-2021-28490 | HIGH | 8.8 | 0.5% | Aug 19, 2021 | In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token. |
| CVE-2021-39302 | CRITICAL | 9.8 | 0.9% | Aug 19, 2021 | MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value. |
| CVE-2021-39138 | MEDIUM | 6.5 | 1.0% | Aug 19, 2021 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can u... |
| CVE-2021-37698 | HIGH | 7.5 | 1.4% | Aug 19, 2021 | Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat... |
| CVE-2021-34645 | HIGH | 8.8 | 0.6% | Aug 19, 2021 | The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_s... |
| CVE-2021-31868 | MEDIUM | 5.4 | 0.5% | Aug 19, 2021 | Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket... |
| CVE-2021-31338 | HIGH | 7.8 | 0.2% | Aug 19, 2021 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to... |
| CVE-2021-29280 | MEDIUM | 6.4 | 0.8% | Aug 19, 2021 | In TP-Link Wireless N Router WR840N an ARP poisoning attack can cause buffer overflow |
| CVE-2021-24038 | HIGH | 7.8 | 0.2% | Aug 19, 2021 | Due to a bug with management of handles in OVRServiceLauncher.exe, an attacker could expose a privileged process handle ... |
| CVE-2021-28002 | MEDIUM | 5.4 | 1.1% | Aug 19, 2021 | A persistent cross-site scripting vulnerability was discovered in the Excerpt parameter in Textpattern CMS 4.9.0 which a... |
| CVE-2021-28001 | MEDIUM | 5.4 | 1.0% | Aug 19, 2021 | A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remo... |
| CVE-2021-28000 | MEDIUM | 4.8 | 0.9% | Aug 19, 2021 | A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project... |
| CVE-2021-27999 | MEDIUM | 4.9 | 0.8% | Aug 19, 2021 | A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System P... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now