2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37541 | MEDIUM | 6.1 | 0.5% | Aug 6, 2021 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. |
| CVE-2021-37540 | MEDIUM | 6.5 | 0.7% | Aug 6, 2021 | In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. |
| CVE-2021-36708 | HIGH | 7.5 | 1.2% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the... |
| CVE-2021-36707 | CRITICAL | 9.8 | 2.6% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter... |
| CVE-2021-36706 | CRITICAL | 9.8 | 2.6% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter ... |
| CVE-2021-36705 | CRITICAL | 9.8 | 2.6% | Aug 6, 2021 | In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter va... |
| CVE-2021-36351 | CRITICAL | 9.8 | 1.9% | Aug 6, 2021 | SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth... |
| CVE-2021-36209 | CRITICAL | 9.8 | 1.0% | Aug 6, 2021 | In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset. |
| CVE-2021-37381 | HIGH | 8.8 | 0.6% | Aug 6, 2021 | Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos t... |
| CVE-2021-22295 | MEDIUM | 5.5 | 0.1% | Aug 6, 2021 | A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to ca... |
| CVE-2021-38152 | MEDIUM | 5.4 | 1.0% | Aug 6, 2021 | index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS. |
| CVE-2021-38151 | MEDIUM | 5.4 | 0.6% | Aug 6, 2021 | index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS. |
| CVE-2021-38149 | MEDIUM | 5.4 | 0.7% | Aug 6, 2021 | index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS. |
| CVE-2021-37388 | CRITICAL | 9.8 | 3.7% | Aug 6, 2021 | A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an att... |
| CVE-2021-32597 | MEDIUM | 5.4 | 0.6% | Aug 6, 2021 | Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions... |
| CVE-2021-32587 | MEDIUM | 4.3 | 0.6% | Aug 6, 2021 | An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a... |
| CVE-2021-3655 | LOW | 3.3 | 0.3% | Aug 5, 2021 | A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP p... |
| CVE-2021-3642 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final ... |
| CVE-2021-3591 | — | — | — | Aug 5, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2021-3580 | HIGH | 7.5 | 2.7% | Aug 5, 2021 | A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could us... |
| CVE-2021-3566 | MEDIUM | 5.5 | 0.9% | Aug 5, 2021 | Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitima... |
| CVE-2021-37632 | HIGH | 8.1 | 1.7% | Aug 5, 2021 | SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn6... |
| CVE-2021-37156 | HIGH | 7.5 | 1.0% | Aug 5, 2021 | Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's ... |
| CVE-2021-35327 | CRITICAL | 9.8 | 1.4% | Aug 5, 2021 | A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, th... |
| CVE-2021-35326 | HIGH | 7.5 | 2.5% | Aug 5, 2021 | A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configura... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now