2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30184 | HIGH | 7.8 | 1.8% | Apr 7, 2021 | GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is relate... |
| CVE-2021-30177 | CRITICAL | 9.8 | 2.4% | Apr 7, 2021 | There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execut... |
| CVE-2021-26709 | CRITICAL | 9.8 | 40.1% | Apr 7, 2021 | D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated... |
| CVE-2021-20692 | HIGH | 7.1 | 1.0% | Apr 7, 2021 | Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker ... |
| CVE-2021-20691 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unsp... |
| CVE-2021-20690 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unsp... |
| CVE-2021-20689 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unsp... |
| CVE-2021-20688 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via uns... |
| CVE-2021-20687 | HIGH | 8.8 | 0.6% | Apr 7, 2021 | Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of... |
| CVE-2021-20686 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecifie... |
| CVE-2021-20685 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecifie... |
| CVE-2021-20684 | MEDIUM | 6.1 | 0.8% | Apr 7, 2021 | Cross-site scripting vulnerability in MagazinegerZ v.1.01 allows remote attackers to inject an arbitrary script via unsp... |
| CVE-2021-1892 | HIGH | 7.8 | 0.2% | Apr 7, 2021 | Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Comput... |
| CVE-2021-30147 | HIGH | 8.8 | 3.5% | Apr 7, 2021 | DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php. |
| CVE-2021-30178 | MEDIUM | 5.5 | 0.3% | Apr 7, 2021 | An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer deref... |
| CVE-2021-27900 | HIGH | 8.1 | 2.5% | Apr 6, 2021 | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several... |
| CVE-2021-27899 | HIGH | 7.4 | 0.6% | Apr 6, 2021 | The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati... |
| CVE-2021-22158 | HIGH | 7.2 | 0.6% | Apr 6, 2021 | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) i... |
| CVE-2021-22157 | MEDIUM | 6.1 | 1.9% | Apr 6, 2021 | Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS. |
| CVE-2021-25692 | MEDIUM | 4.6 | 0.2% | Apr 6, 2021 | Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway pri... |
| CVE-2021-21404 | HIGH | 7.5 | 2.0% | Apr 6, 2021 | Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv... |
| CVE-2021-28688 | MEDIUM | 6.5 | 0.3% | Apr 6, 2021 | The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or ... |
| CVE-2021-21423 | HIGH | 8.1 | 1.4% | Apr 6, 2021 | `projen` is a project generation tool that synthesizes project configuration files such as `package.json`, `tsconfig.jso... |
| CVE-2021-24027 | HIGH | 7.5 | 3.8% | Apr 6, 2021 | A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may ha... |
| CVE-2021-24026 | CRITICAL | 9.8 | 1.4% | Apr 6, 2021 | A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, W... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now