2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37366 | HIGH | 8.8 | 0.5% | Aug 10, 2021 | CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining... |
| CVE-2021-37365 | MEDIUM | 6.1 | 0.7% | Aug 10, 2021 | CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_hel... |
| CVE-2021-32768 | MEDIUM | 6.1 | 0.7% | Aug 10, 2021 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing... |
| CVE-2021-38373 | MEDIUM | 5.3 | 0.5% | Aug 10, 2021 | In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Ser... |
| CVE-2021-38372 | LOW | 3.7 | 0.8% | Aug 10, 2021 | In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server ar... |
| CVE-2021-38371 | HIGH | 7.5 | 2.0% | Aug 10, 2021 | The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending. |
| CVE-2021-38370 | MEDIUM | 5.9 | 1.6% | Aug 10, 2021 | In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. |
| CVE-2021-36601 | MEDIUM | 6.1 | 0.9% | Aug 10, 2021 | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settin... |
| CVE-2021-33707 | MEDIUM | 6.1 | 2.0% | Aug 10, 2021 | SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing ... |
| CVE-2021-33706 | MEDIUM | 4.3 | 0.6% | Aug 10, 2021 | Due to improper input validation in InfraBox, logs can be modified by an authenticated user. |
| CVE-2021-33703 | MEDIUM | 6.1 | 1.5% | Aug 10, 2021 | Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode U... |
| CVE-2021-33702 | MEDIUM | 6.1 | 1.5% | Aug 10, 2021 | Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suf... |
| CVE-2021-33699 | MEDIUM | 6.5 | 1.2% | Aug 10, 2021 | Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in ... |
| CVE-2021-32943 | CRITICAL | 9.8 | 1.9% | Aug 10, 2021 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arb... |
| CVE-2021-22676 | MEDIUM | 6.1 | 0.6% | Aug 10, 2021 | UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to se... |
| CVE-2021-38365 | LOW | 3.7 | 1.2% | Aug 10, 2021 | Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the po... |
| CVE-2021-37152 | MEDIUM | 5.4 | 24.4% | Aug 10, 2021 | Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the abili... |
| CVE-2021-29739 | MEDIUM | 4.9 | 1.1% | Aug 10, 2021 | IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is ret... |
| CVE-2021-22674 | MEDIUM | 6.5 | 1.1% | Aug 10, 2021 | The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unautho... |
| CVE-2021-22386 | HIGH | 7 | 0.2% | Aug 10, 2021 | A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to ... |
| CVE-2021-22385 | HIGH | 7.8 | 0.2% | Aug 10, 2021 | A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local atta... |
| CVE-2021-31655 | MEDIUM | 6.1 | 1.0% | Aug 10, 2021 | Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter.... |
| CVE-2021-3689 | HIGH | 7.5 | 1.9% | Aug 10, 2021 | yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator |
| CVE-2021-37180 | HIGH | 7.8 | 1.4% | Aug 10, 2021 | A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library lacks prop... |
| CVE-2021-37179 | HIGH | 7.8 | 1.4% | Aug 10, 2021 | A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library in affecte... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now