2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4149 | MEDIUM | 5.5 | 0.4% | Mar 23, 2022 | A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock op... |
| CVE-2021-4148 | MEDIUM | 5.5 | 0.3% | Mar 23, 2022 | A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity ... |
| CVE-2021-27430 | MEDIUM | 6.8 | 0.2% | Mar 23, 2022 | GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with phy... |
| CVE-2021-27424 | MEDIUM | 5.3 | 0.8% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the communications guide. GE was made ... |
| CVE-2021-27420 | MEDIUM | 5.3 | 1.0% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of unsupported HTTP verbs... |
| CVE-2021-27418 | MEDIUM | 6.1 | 0.6% | Mar 23, 2022 | GE UR firmware versions prior to version 8.1x supports web interface with read-only access. The device fails to properly... |
| CVE-2021-43737 | MEDIUM | 6.5 | 0.4% | Mar 23, 2022 | An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account... |
| CVE-2021-25220 | MEDIUM | 6.8 | 3.3% | Mar 23, 2022 | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.... |
| CVE-2021-33961 | MEDIUM | 6.1 | 0.7% | Mar 22, 2022 | A Cross Site Scripting (XSS) vulnerabililty exists in enhanced-github v5.0.11 via the file name parameter. |
| CVE-2021-38745 | MEDIUM | 6.8 | 0.8% | Mar 21, 2022 | Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execu... |
| CVE-2021-46390 | MEDIUM | 6.8 | 0.5% | Mar 21, 2022 | An access control issue in the authentication module of Lexar_F35 v1.0.34 allows attackers to access sensitive data and ... |
| CVE-2021-25019 | MEDIUM | 6.1 | 0.8% | Mar 21, 2022 | The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it b... |
| CVE-2021-45117 | MEDIUM | 6.5 | 1.4% | Mar 21, 2022 | The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointe... |
| CVE-2021-44760 | MEDIUM | 5.4 | 0.5% | Mar 18, 2022 | Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 vers... |
| CVE-2021-27789 | MEDIUM | 6.5 | 0.8% | Mar 18, 2022 | The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements... |
| CVE-2021-23209 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP ... |
| CVE-2021-23150 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pag... |
| CVE-2021-39046 | MEDIUM | 4.9 | 0.9% | Mar 18, 2022 | IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user cre... |
| CVE-2021-29899 | MEDIUM | 6.5 | 1.0% | Mar 18, 2022 | IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of ser... |
| CVE-2021-22571 | MEDIUM | 5.5 | 0.2% | Mar 18, 2022 | A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process ... |
| CVE-2021-45868 | MEDIUM | 5.5 | 1.3% | Mar 18, 2022 | In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk).... |
| CVE-2021-43961 | MEDIUM | 4.3 | 0.7% | Mar 17, 2022 | Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection. |
| CVE-2021-44261 | MEDIUM | 5.3 | 20.8% | Mar 17, 2022 | A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote at... |
| CVE-2021-23771 | MEDIUM | 6.5 | 1.0% | Mar 17, 2022 | This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox E... |
| CVE-2021-45792 | MEDIUM | 4.8 | 0.5% | Mar 17, 2022 | Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now