2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24019 | CRITICAL | 9.8 | 3.8% | Oct 6, 2021 | An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below ... |
| CVE-2021-3625 | CRITICAL | 9.8 | 2.3% | Oct 5, 2021 | Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For mo... |
| CVE-2021-3319 | CRITICAL | 9.8 | 0.9% | Oct 5, 2021 | DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Poi... |
| CVE-2021-41116 | CRITICAL | 9.8 | 2.9% | Oct 5, 2021 | Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer ... |
| CVE-2021-41553 | CRITICAL | 9.8 | 1.2% | Oct 5, 2021 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session t... |
| CVE-2021-41773 | CRITICAL | 9.8 | 100.0% | Oct 5, 2021 | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path trave... |
| CVE-2021-41100 | CRITICAL | 9.8 | 1.0% | Oct 4, 2021 | Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is poss... |
| CVE-2021-41093 | CRITICAL | 9.8 | 1.4% | Oct 4, 2021 | Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they... |
| CVE-2021-23857 | CRITICAL | 9.8 | 1.2% | Oct 4, 2021 | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the... |
| CVE-2021-41592 | CRITICAL | 9.4 | 1.5% | Oct 4, 2021 | Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. |
| CVE-2021-41591 | CRITICAL | 9.4 | 1.7% | Oct 4, 2021 | ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure. |
| CVE-2021-35296 | CRITICAL | 9.8 | 1.9% | Oct 4, 2021 | An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via m... |
| CVE-2021-41868 | CRITICAL | 9.8 | 2.3% | Oct 4, 2021 | OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --... |
| CVE-2021-38823 | CRITICAL | 9.8 | 1.5% | Oct 4, 2021 | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not ... |
| CVE-2021-37333 | CRITICAL | 9.8 | 1.4% | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.or... |
| CVE-2021-41511 | CRITICAL | 9.8 | 3.2% | Oct 4, 2021 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by usin... |
| CVE-2021-40323 | CRITICAL | 9.8 | 88.5% | Oct 4, 2021 | Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo... |
| CVE-2021-41862 | CRITICAL | 9.8 | 1.9% | Oct 2, 2021 | AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (... |
| CVE-2021-36298 | CRITICAL | 9.8 | 0.8% | Oct 1, 2021 | Dell EMC InsightIQ, versions prior to 4.1.4, contain risky cryptographic algorithms in the SSH component. A remote unaut... |
| CVE-2021-41647 | CRITICAL | 9.1 | 1.9% | Oct 1, 2021 | An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Or... |
| CVE-2021-3825 | CRITICAL | 9.6 | 1.6% | Oct 1, 2021 | On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. ... |
| CVE-2021-41649 | CRITICAL | 9.8 | 51.8% | Oct 1, 2021 | An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php c... |
| CVE-2021-40960 | CRITICAL | 9.8 | 9.8% | Oct 1, 2021 | Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd... |
| CVE-2021-41110 | CRITICAL | 9.8 | 2.7% | Oct 1, 2021 | cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a D... |
| CVE-2021-34352 | CRITICAL | 9.8 | 1.5% | Oct 1, 2021 | A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now