2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33926 | HIGH | 8.8 | 1.0% | Feb 17, 2023 | An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5.... |
| CVE-2021-33391 | CRITICAL | 9.8 | 1.1% | Feb 17, 2023 | An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() funct... |
| CVE-2021-33237 | — | — | — | Feb 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Consult IDs: CVE-2021-36686. Reason: This candidate is a duplicate of... |
| CVE-2021-33226 | CRITICAL | 9.8 | 1.6% | Feb 17, 2023 | Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func vari... |
| CVE-2021-32441 | HIGH | 7.5 | 0.6% | Feb 17, 2023 | SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive informat... |
| CVE-2021-32419 | MEDIUM | 5.3 | 0.6% | Feb 17, 2023 | An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm... |
| CVE-2021-32163 | CRITICAL | 9.8 | 0.9% | Feb 17, 2023 | Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorizatio... |
| CVE-2021-32142 | HIGH | 7.8 | 0.4% | Feb 17, 2023 | Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_... |
| CVE-2021-43529 | CRITICAL | 9.8 | 0.5% | Feb 16, 2023 | Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/M... |
| CVE-2021-23980 | MEDIUM | 6.1 | 0.5% | Feb 16, 2023 | A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags s... |
| CVE-2021-33104 | MEDIUM | 5.5 | 0.3% | Feb 16, 2023 | Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potential... |
| CVE-2021-0187 | HIGH | 8.2 | 0.2% | Feb 16, 2023 | Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially ena... |
| CVE-2021-43074 | MEDIUM | 4.3 | 0.3% | Feb 16, 2023 | An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and bel... |
| CVE-2021-42761 | CRITICAL | 9.8 | 1.5% | Feb 16, 2023 | A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions... |
| CVE-2021-42756 | CRITICAL | 9.8 | 36.4% | Feb 16, 2023 | Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a... |
| CVE-2021-40555 | MEDIUM | 5.4 | 0.4% | Feb 16, 2023 | Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via descripti... |
| CVE-2021-38239 | HIGH | 7.5 | 0.7% | Feb 15, 2023 | SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders para... |
| CVE-2021-34117 | HIGH | 7.5 | 0.9% | Feb 15, 2023 | SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, al... |
| CVE-2021-33925 | CRITICAL | 9.8 | 1.0% | Feb 15, 2023 | SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May ... |
| CVE-2021-33396 | MEDIUM | 6.5 | 0.3% | Feb 15, 2023 | Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other inf... |
| CVE-2021-33304 | CRITICAL | 9.8 | 0.8% | Feb 15, 2023 | Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pi... |
| CVE-2021-46023 | HIGH | 7.5 | 0.8% | Feb 14, 2023 | An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability caus... |
| CVE-2021-42793 | — | — | — | Feb 9, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2021-42792 | — | — | — | Feb 9, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2021-41064 | — | — | — | Feb 9, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now