2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42202 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter... |
| CVE-2021-42200 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located i... |
| CVE-2021-42198 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() lo... |
| CVE-2021-42196 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() l... |
| CVE-2021-36890 | MEDIUM | 4.3 | 0.4% | Jun 2, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress. |
| CVE-2021-36866 | MEDIUM | 4.8 | 0.5% | Jun 2, 2022 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables... |
| CVE-2021-33504 | MEDIUM | 4.9 | 0.7% | Jun 2, 2022 | Couchbase Server before 7.1.0 has Incorrect Access Control. |
| CVE-2021-27914 | MEDIUM | 4.8 | 0.4% | Jun 1, 2022 | A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject exe... |
| CVE-2021-27778 | MEDIUM | 4.8 | 0.4% | Jun 1, 2022 | HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Appro... |
| CVE-2021-27781 | MEDIUM | 4.8 | 0.4% | May 27, 2022 | The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. |
| CVE-2021-27780 | MEDIUM | 5.3 | 0.7% | May 27, 2022 | The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment. |
| CVE-2021-28509 | MEDIUM | 6.1 | 0.4% | May 26, 2022 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te... |
| CVE-2021-28508 | MEDIUM | 6.1 | 0.5% | May 26, 2022 | This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te... |
| CVE-2021-4232 | MEDIUM | 6.1 | 0.5% | May 26, 2022 | A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function o... |
| CVE-2021-4231 | MEDIUM | 5.4 | 1.1% | May 26, 2022 | A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the ... |
| CVE-2021-42692 | MEDIUM | 6.5 | 0.8% | May 26, 2022 | There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS. |
| CVE-2021-27783 | MEDIUM | 6.5 | 0.3% | May 25, 2022 | User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed. |
| CVE-2021-35487 | MEDIUM | 6.5 | 1.0% | May 25, 2022 | Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection atta... |
| CVE-2021-32989 | MEDIUM | 6.1 | 2.2% | May 25, 2022 | When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns erro... |
| CVE-2021-44974 | MEDIUM | 5.5 | 0.8% | May 25, 2022 | radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol par... |
| CVE-2021-3629 | MEDIUM | 5.9 | 1.2% | May 24, 2022 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potenti... |
| CVE-2021-3597 | MEDIUM | 5.9 | 1.1% | May 24, 2022 | A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting ... |
| CVE-2021-32964 | MEDIUM | 5.3 | 0.8% | May 24, 2022 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an a... |
| CVE-2021-32962 | MEDIUM | 6.1 | 0.7% | May 24, 2022 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an atta... |
| CVE-2021-44975 | MEDIUM | 5.5 | 0.9% | May 24, 2022 | radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now