2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41849 | MEDIUM | 5.5 | 0.2% | Mar 11, 2022 | An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Inform... |
| CVE-2021-44667 | MEDIUM | 6.1 | 0.8% | Mar 11, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo param... |
| CVE-2021-33150 | MEDIUM | 6.8 | 0.3% | Mar 11, 2022 | Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an un... |
| CVE-2021-32478 | MEDIUM | 6.1 | 1.2% | Mar 11, 2022 | The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect ... |
| CVE-2021-32477 | MEDIUM | 4.3 | 0.7% | Mar 11, 2022 | The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with ... |
| CVE-2021-32475 | MEDIUM | 5.4 | 0.6% | Mar 11, 2022 | ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10... |
| CVE-2021-32473 | MEDIUM | 5.3 | 1.0% | Mar 11, 2022 | It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.1... |
| CVE-2021-32472 | MEDIUM | 4.3 | 0.7% | Mar 11, 2022 | Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle ve... |
| CVE-2021-32009 | MEDIUM | 6.1 | 0.5% | Mar 11, 2022 | Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject java... |
| CVE-2021-27416 | MEDIUM | 5.4 | 0.6% | Mar 11, 2022 | An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versio... |
| CVE-2021-27414 | MEDIUM | 6.1 | 0.6% | Mar 11, 2022 | An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to an... |
| CVE-2021-26401 | MEDIUM | 5.6 | 0.3% | Mar 11, 2022 | LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. |
| CVE-2021-26341 | MEDIUM | 6.5 | 0.3% | Mar 11, 2022 | Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage... |
| CVE-2021-46708 | MEDIUM | 6.1 | 1.4% | Mar 11, 2022 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the ... |
| CVE-2021-44585 | MEDIUM | 6.1 | 0.9% | Mar 10, 2022 | A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event. |
| CVE-2021-41233 | MEDIUM | 5.3 | 0.8% | Mar 10, 2022 | Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with t... |
| CVE-2021-39025 | MEDIUM | 5.3 | 0.6% | Mar 10, 2022 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backe... |
| CVE-2021-38910 | MEDIUM | 5.3 | 1.1% | Mar 10, 2022 | IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused ... |
| CVE-2021-4095 | MEDIUM | 5.5 | 0.4% | Mar 10, 2022 | A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU... |
| CVE-2021-4023 | MEDIUM | 5.5 | 0.2% | Mar 10, 2022 | A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic... |
| CVE-2021-44421 | MEDIUM | 5.5 | 0.4% | Mar 10, 2022 | The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that al... |
| CVE-2021-44269 | MEDIUM | 5.5 | 1.2% | Mar 10, 2022 | An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPack... |
| CVE-2021-44216 | MEDIUM | 5.5 | 0.4% | Mar 10, 2022 | Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unautho... |
| CVE-2021-44215 | MEDIUM | 5.5 | 0.3% | Mar 10, 2022 | Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users ... |
| CVE-2021-43969 | MEDIUM | 6.5 | 1.5% | Mar 10, 2022 | The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Intera... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now