2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25955 | CRITICAL | 9 | 0.9% | Aug 15, 2021 | In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows l... |
| CVE-2021-38699 | MEDIUM | 5.4 | 8.0% | Aug 15, 2021 | TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs. |
| CVE-2021-37326 | MEDIUM | 5.3 | 0.8% | Aug 15, 2021 | NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations. |
| CVE-2021-21815 | HIGH | 7.8 | 0.3% | Aug 13, 2021 | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs'... |
| CVE-2021-21814 | HIGH | 7.8 | 0.3% | Aug 13, 2021 | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman... |
| CVE-2021-21813 | HIGH | 7.8 | 0.3% | Aug 13, 2021 | Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman... |
| CVE-2021-21812 | HIGH | 7.8 | 0.3% | Aug 13, 2021 | A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’... |
| CVE-2021-37705 | CRITICAL | 10 | 2.4% | Aug 13, 2021 | OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incompl... |
| CVE-2021-21830 | CRITICAL | 9.8 | 2.3% | Aug 13, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ X... |
| CVE-2021-21829 | CRITICAL | 9.8 | 2.5% | Aug 13, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem funct... |
| CVE-2021-38623 | HIGH | 7.5 | 1.0% | Aug 13, 2021 | The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service ... |
| CVE-2021-38302 | CRITICAL | 9.8 | 1.0% | Aug 13, 2021 | The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection. |
| CVE-2021-36793 | HIGH | 7.5 | 1.0% | Aug 13, 2021 | The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitiv... |
| CVE-2021-36792 | HIGH | 7.2 | 0.7% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various ap... |
| CVE-2021-36791 | MEDIUM | 5.3 | 0.8% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registrat... |
| CVE-2021-36790 | MEDIUM | 6.1 | 0.6% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. |
| CVE-2021-36789 | CRITICAL | 9.8 | 1.0% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. |
| CVE-2021-36788 | MEDIUM | 5.4 | 0.5% | Aug 13, 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. |
| CVE-2021-36787 | MEDIUM | 5.4 | 1.3% | Aug 13, 2021 | The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document. |
| CVE-2021-36786 | HIGH | 7.5 | 1.0% | Aug 13, 2021 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credent... |
| CVE-2021-36785 | MEDIUM | 5.4 | 0.5% | Aug 13, 2021 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS. |
| CVE-2021-34823 | CRITICAL | 9.1 | 2.0% | Aug 13, 2021 | The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in... |
| CVE-2021-3352 | CRITICAL | 9.1 | 1.0% | Aug 13, 2021 | The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0... |
| CVE-2021-38554 | MEDIUM | 5.3 | 0.9% | Aug 13, 2021 | HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a singl... |
| CVE-2021-38553 | MEDIUM | 4.4 | 0.3% | Aug 13, 2021 | HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Int... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now