2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44081 | HIGH | 7.5 | 1.0% | Mar 29, 2022 | A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 character... |
| CVE-2021-44581 | HIGH | 7.5 | 1.0% | Mar 29, 2022 | An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter. |
| CVE-2021-43103 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote m... |
| CVE-2021-43102 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote ma... |
| CVE-2021-43101 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a... |
| CVE-2021-43100 | HIGH | 7.2 | 1.5% | Mar 28, 2022 | A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote m... |
| CVE-2021-43098 | HIGH | 7.2 | 1.2% | Mar 28, 2022 | A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. |
| CVE-2021-43097 | HIGH | 7.2 | 2.2% | Mar 28, 2022 | A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a ma... |
| CVE-2021-25068 | HIGH | 7.2 | 1.3% | Mar 28, 2022 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter wh... |
| CVE-2021-25064 | HIGH | 7.2 | 1.3% | Mar 28, 2022 | The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a... |
| CVE-2021-24962 | HIGH | 8.8 | 2.8% | Mar 28, 2022 | The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to ... |
| CVE-2021-44124 | HIGH | 7.5 | 1.9% | Mar 28, 2022 | Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input d... |
| CVE-2021-26601 | HIGH | 8.1 | 3.2% | Mar 28, 2022 | ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal. |
| CVE-2021-40905 | HIGH | 8.8 | 3.2% | Mar 25, 2022 | The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uplo... |
| CVE-2021-40904 | HIGH | 8.8 | 3.8% | Mar 25, 2022 | The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dok... |
| CVE-2021-44683 | HIGH | 8.2 | 1.0% | Mar 25, 2022 | The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open functi... |
| CVE-2021-44905 | HIGH | 8.2 | 1.3% | Mar 25, 2022 | Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attac... |
| CVE-2021-4202 | HIGH | 7 | 0.4% | Mar 25, 2022 | A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kern... |
| CVE-2021-4157 | HIGH | 8 | 1.6% | Mar 25, 2022 | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users... |
| CVE-2021-44477 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD paramete... |
| CVE-2021-44462 | HIGH | 7.1 | 0.7% | Mar 25, 2022 | This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionR... |
| CVE-2021-3814 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut... |
| CVE-2021-3567 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-... |
| CVE-2021-3422 | HIGH | 7.5 | 0.6% | Mar 25, 2022 | The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk En... |
| CVE-2021-35254 | HIGH | 8.8 | 1.0% | Mar 25, 2022 | SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds ha... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now