2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44213 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. |
| CVE-2021-44212 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring. |
| CVE-2021-44211 | MEDIUM | 5.4 | 0.7% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature. |
| CVE-2021-44210 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data. |
| CVE-2021-44209 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. |
| CVE-2021-44208 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. |
| CVE-2021-26598 | MEDIUM | 5.3 | 10.8% | Mar 28, 2022 | ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta... |
| CVE-2021-40906 | MEDIUM | 6.1 | 1.0% | Mar 25, 2022 | CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in... |
| CVE-2021-4203 | MEDIUM | 6.8 | 1.8% | Mar 25, 2022 | A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race w... |
| CVE-2021-4147 | MEDIUM | 6.5 | 0.2% | Mar 25, 2022 | A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on t... |
| CVE-2021-44768 | MEDIUM | 5.5 | 0.7% | Mar 25, 2022 | Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specifi... |
| CVE-2021-3941 | MEDIUM | 6.5 | 0.3% | Mar 25, 2022 | In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x -... |
| CVE-2021-3933 | MEDIUM | 5.5 | 0.8% | Mar 25, 2022 | An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could caus... |
| CVE-2021-3582 | MEDIUM | 6.5 | 0.4% | Mar 25, 2022 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRD... |
| CVE-2021-22100 | MEDIUM | 5.3 | 0.9% | Mar 25, 2022 | In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker... |
| CVE-2021-20323 | MEDIUM | 6.1 | 37.2% | Mar 25, 2022 | A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. |
| CVE-2021-20290 | MEDIUM | 6.1 | 0.2% | Mar 25, 2022 | An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman cli... |
| CVE-2021-46426 | MEDIUM | 6.1 | 0.9% | Mar 25, 2022 | phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functiona... |
| CVE-2021-44751 | MEDIUM | 5.3 | 0.6% | Mar 25, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in... |
| CVE-2021-39491 | MEDIUM | 5.4 | 0.5% | Mar 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan ... |
| CVE-2021-43659 | MEDIUM | 5.4 | 0.5% | Mar 24, 2022 | In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, wh... |
| CVE-2021-28275 | MEDIUM | 5.5 | 0.7% | Mar 23, 2022 | A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exi... |
| CVE-2021-4219 | MEDIUM | 5.5 | 1.0% | Mar 23, 2022 | A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of... |
| CVE-2021-4180 | MEDIUM | 4.3 | 0.8% | Mar 23, 2022 | An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or ... |
| CVE-2021-4150 | MEDIUM | 5.5 | 0.3% | Mar 23, 2022 | A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker wi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now