2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43081 | MEDIUM | 6.1 | 0.8% | May 11, 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below... |
| CVE-2021-39700 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In the policies of adbd.te, there was a logic error which caused the CTS Listening Ports Test to report invalid results.... |
| CVE-2021-39670 | MEDIUM | 5.5 | 0.2% | May 10, 2022 | In setStream of WallpaperManager.java, there is a possible way to cause a permanent DoS due to improper input validation... |
| CVE-2021-26390 | MEDIUM | 6.2 | 0.2% | May 10, 2022 | A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to... |
| CVE-2021-26352 | MEDIUM | 5.5 | 0.2% | May 10, 2022 | Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to inval... |
| CVE-2021-39024 | MEDIUM | 6.1 | 0.4% | May 10, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2021-43712 | MEDIUM | 5.4 | 0.9% | May 9, 2022 | Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker t... |
| CVE-2021-27764 | MEDIUM | 6.5 | 0.5% | May 6, 2022 | Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie ... |
| CVE-2021-27760 | MEDIUM | 5.5 | 0.7% | May 6, 2022 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime c... |
| CVE-2021-27759 | MEDIUM | 6.5 | 0.3% | May 6, 2022 | This vulnerability arises because the application allows the user to perform some sensitive action without verifying tha... |
| CVE-2021-27758 | MEDIUM | 6.5 | 0.3% | May 6, 2022 | There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after... |
| CVE-2021-36912 | MEDIUM | 5.4 | 0.5% | May 6, 2022 | Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress,... |
| CVE-2021-33845 | MEDIUM | 5.3 | 0.8% | May 6, 2022 | The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerabilit... |
| CVE-2021-39027 | MEDIUM | 5 | 0.3% | May 6, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another componen... |
| CVE-2021-44054 | MEDIUM | 6.1 | 0.5% | May 5, 2022 | An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploite... |
| CVE-2021-44053 | MEDIUM | 6.1 | 0.7% | May 5, 2022 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud.... |
| CVE-2021-38693 | MEDIUM | 5.3 | 0.9% | May 5, 2022 | A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Applia... |
| CVE-2021-39020 | MEDIUM | 5.3 | 0.5% | May 5, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to in... |
| CVE-2021-45783 | MEDIUM | 4.6 | 1.9% | May 5, 2022 | Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to... |
| CVE-2021-43206 | MEDIUM | 4.3 | 0.7% | May 4, 2022 | A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through... |
| CVE-2021-41032 | MEDIUM | 5.4 | 0.5% | May 4, 2022 | An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an ... |
| CVE-2021-27411 | MEDIUM | 6.5 | 0.8% | May 3, 2022 | Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCr... |
| CVE-2021-39390 | MEDIUM | 5.4 | 0.6% | May 3, 2022 | Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter. |
| CVE-2021-4138 | MEDIUM | 5.3 | 0.8% | May 2, 2022 | Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified ho... |
| CVE-2021-42528 | MEDIUM | 5.5 | 1.8% | May 2, 2022 | XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially craft... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now