2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37394 | HIGH | 8.8 | 1.2% | Jul 26, 2021 | In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user reg... |
| CVE-2021-37393 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can ... |
| CVE-2021-37392 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API ... |
| CVE-2021-36563 | MEDIUM | 5.4 | 1.7% | Jul 26, 2021 | The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the W... |
| CVE-2021-32792 | MEDIUM | 6.1 | 1.5% | Jul 26, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-32791 | MEDIUM | 5.9 | 1.5% | Jul 26, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-32790 | MEDIUM | 4.9 | 1.3% | Jul 26, 2021 | Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit... |
| CVE-2021-31292 | HIGH | 7.5 | 2.6% | Jul 26, 2021 | An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and... |
| CVE-2021-31291 | — | — | — | Jul 26, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of ... |
| CVE-2021-25804 | HIGH | 7.5 | 1.8% | Jul 26, 2021 | A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the a... |
| CVE-2021-25803 | HIGH | 7.1 | 0.7% | Jul 26, 2021 | A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows att... |
| CVE-2021-25802 | HIGH | 7.1 | 0.7% | Jul 26, 2021 | A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attacker... |
| CVE-2021-25801 | HIGH | 7.1 | 1.5% | Jul 26, 2021 | A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to ca... |
| CVE-2021-32789 | HIGH | 7.5 | 17.2% | Jul 26, 2021 | woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerabilit... |
| CVE-2021-32631 | MEDIUM | 6.5 | 1.1% | Jul 26, 2021 | Common is a package of common modules that can be accessed by NIMBLE services. Common before commit number 3b96cb0293d34... |
| CVE-2021-33629 | HIGH | 7.5 | 1.0% | Jul 26, 2021 | isula-build before 0.9.5-6 can cause a program crash, when building container images, some functions for processing exte... |
| CVE-2021-37534 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster. |
| CVE-2021-26824 | HIGH | 7.1 | 0.4% | Jul 26, 2021 | DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing lo... |
| CVE-2021-3664 | MEDIUM | 5.3 | 1.8% | Jul 26, 2021 | url-parse is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-35030 | MEDIUM | 4.3 | 0.3% | Jul 26, 2021 | A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize p... |
| CVE-2021-29784 | MEDIUM | 4.3 | 1.0% | Jul 26, 2021 | IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2021-29770 | MEDIUM | 6.5 | 0.6% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform ... |
| CVE-2021-29769 | MEDIUM | 4.3 | 0.5% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authoriz... |
| CVE-2021-29767 | MEDIUM | 5.3 | 1.3% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information ... |
| CVE-2021-29766 | MEDIUM | 5.3 | 1.3% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now