2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43444 | HIGH | 7.5 | 1.2% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be f... |
| CVE-2021-24881 | HIGH | 7.5 | 0.8% | Jan 23, 2023 | The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed... |
| CVE-2021-24837 | MEDIUM | 5.4 | 0.4% | Jan 23, 2023 | The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow user... |
| CVE-2021-33642 | MEDIUM | 5.5 | 0.2% | Jan 20, 2023 | When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function. |
| CVE-2021-33641 | HIGH | 7.8 | 0.3% | Jan 20, 2023 | When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses... |
| CVE-2021-39089 | MEDIUM | 6.5 | 0.7% | Jan 20, 2023 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive inform... |
| CVE-2021-39011 | MEDIUM | 4.9 | 0.6% | Jan 20, 2023 | IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that ... |
| CVE-2021-29368 | HIGH | 8.8 | 0.7% | Jan 20, 2023 | Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 all... |
| CVE-2021-26644 | CRITICAL | 9.8 | 0.9% | Jan 20, 2023 | SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mang... |
| CVE-2021-26642 | CRITICAL | 9.8 | 1.2% | Jan 20, 2023 | When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file... |
| CVE-2021-37500 | HIGH | 8.1 | 1.2% | Jan 20, 2023 | Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics funct... |
| CVE-2021-37499 | MEDIUM | 6.5 | 0.9% | Jan 20, 2023 | CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View Lice... |
| CVE-2021-37498 | MEDIUM | 6.5 | 0.8% | Jan 20, 2023 | An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers... |
| CVE-2021-27782 | HIGH | 7.5 | 0.3% | Jan 20, 2023 | HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked ou... |
| CVE-2021-37774 | HIGH | 8 | 0.9% | Jan 19, 2023 | An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code... |
| CVE-2021-4314 | MEDIUM | 5.3 | 0.4% | Jan 18, 2023 | It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT to... |
| CVE-2021-33959 | HIGH | 7.5 | 15.0% | Jan 18, 2023 | Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service. |
| CVE-2021-36630 | HIGH | 7.5 | 2.4% | Jan 18, 2023 | DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote at... |
| CVE-2021-32837 | HIGH | 7.5 | 26.7% | Jan 17, 2023 | mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerab... |
| CVE-2021-36647 | MEDIUM | 4.7 | 0.2% | Jan 17, 2023 | Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS ... |
| CVE-2021-46799 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2021-46796 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2021-46793 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2021-46761 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2021-26405 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now