2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22848 | CRITICAL | 9.8 | 1.0% | Mar 18, 2021 | HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL pa... |
| CVE-2021-28681 | MEDIUM | 5.3 | 0.7% | Mar 18, 2021 | Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerCo... |
| CVE-2021-28667 | HIGH | 7.5 | 2.2% | Mar 18, 2021 | StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. Thi... |
| CVE-2021-20678 | HIGH | 8.8 | 2.0% | Mar 18, 2021 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to... |
| CVE-2021-20676 | MEDIUM | 4.3 | 0.8% | Mar 18, 2021 | M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve... |
| CVE-2021-20675 | MEDIUM | 6.5 | 1.3% | Mar 18, 2021 | M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve... |
| CVE-2021-20634 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to ... |
| CVE-2021-20633 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to byp... |
| CVE-2021-20632 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers... |
| CVE-2021-20631 | MEDIUM | 6.5 | 0.7% | Mar 18, 2021 | Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to... |
| CVE-2021-20630 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers... |
| CVE-2021-20629 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbi... |
| CVE-2021-20628 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a... |
| CVE-2021-20627 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a... |
| CVE-2021-20626 | MEDIUM | 6.5 | 0.8% | Mar 18, 2021 | Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to by... |
| CVE-2021-20625 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attack... |
| CVE-2021-20624 | MEDIUM | 6.5 | 0.8% | Mar 18, 2021 | Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to... |
| CVE-2021-28660 | HIGH | 8.8 | 1.3% | Mar 17, 2021 | rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyo... |
| CVE-2021-20200 | — | — | — | Mar 17, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-27292 | HIGH | 7.5 | 3.4% | Mar 17, 2021 | ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attac... |
| CVE-2021-27291 | HIGH | 7.5 | 3.8% | Mar 17, 2021 | In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. So... |
| CVE-2021-22860 | CRITICAL | 9.8 | 2.6% | Mar 17, 2021 | EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vul... |
| CVE-2021-22859 | CRITICAL | 9.8 | 3.8% | Mar 17, 2021 | The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remo... |
| CVE-2021-28650 | MEDIUM | 5.5 | 0.5% | Mar 17, 2021 | autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Dire... |
| CVE-2021-3344 | HIGH | 8.8 | 1.2% | Mar 16, 2021 | A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now