2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24288 | MEDIUM | 6.1 | 1.9% | May 17, 2021 | When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to G... |
| CVE-2021-27734 | CRITICAL | 9.8 | 1.3% | May 17, 2021 | Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers... |
| CVE-2021-32403 | HIGH | 8.8 | 2.5% | May 17, 2021 | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of security mecha... |
| CVE-2021-32402 | HIGH | 8.8 | 0.5% | May 17, 2021 | Intelbras Router RF 301K Firmware 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) due to lack of validation and... |
| CVE-2021-31728 | HIGH | 7.8 | 3.4% | May 17, 2021 | Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 allows a non-privileged process to... |
| CVE-2021-31727 | HIGH | 7.8 | 0.4% | May 17, 2021 | Incorrect access control in zam64.sys, zam32.sys in MalwareFox AntiMalware 2.74.0.150 where IOCTL's 0x80002014, 0x800020... |
| CVE-2021-27342 | MEDIUM | 5.9 | 4.6% | May 17, 2021 | An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0... |
| CVE-2021-3483 | HIGH | 7.8 | 0.4% | May 17, 2021 | A flaw was found in the Nosy driver in the Linux kernel. This issue allows a device to be inserted twice into a doubly-l... |
| CVE-2021-29052 | MEDIUM | 4.3 | 0.8% | May 17, 2021 | The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permi... |
| CVE-2021-29051 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5... |
| CVE-2021-29048 | MEDIUM | 6.1 | 0.9% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 ... |
| CVE-2021-29053 | HIGH | 8.8 | 1.2% | May 17, 2021 | Multiple SQL injection vulnerabilities in Liferay Portal 7.3.5 and Liferay DXP 7.3 before fix pack 1 allow remote authen... |
| CVE-2021-29046 | MEDIUM | 6.1 | 0.9% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and... |
| CVE-2021-29045 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.... |
| CVE-2021-29044 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal ... |
| CVE-2021-29043 | MEDIUM | 5.9 | 0.8% | May 17, 2021 | The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pa... |
| CVE-2021-29047 | HIGH | 7.5 | 1.1% | May 16, 2021 | The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidat... |
| CVE-2021-29041 | MEDIUM | 6.5 | 1.1% | May 16, 2021 | Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 all... |
| CVE-2021-29040 | MEDIUM | 5.3 | 1.1% | May 16, 2021 | The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 2... |
| CVE-2021-29039 | MEDIUM | 6.1 | 0.8% | May 16, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 al... |
| CVE-2021-22668 | CRITICAL | 9.8 | 1.8% | May 16, 2021 | Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulne... |
| CVE-2021-32073 | HIGH | 8.8 | 1.2% | May 15, 2021 | DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web m... |
| CVE-2021-33034 | HIGH | 7.8 | 0.8% | May 14, 2021 | In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5... |
| CVE-2021-33033 | HIGH | 7.8 | 0.6% | May 14, 2021 | The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and C... |
| CVE-2021-3402 | CRITICAL | 9.1 | 2.2% | May 14, 2021 | An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now