2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46113 | HIGH | 8.8 | 3.1% | Jan 25, 2022 | In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by ... |
| CVE-2021-45845 | HIGH | 7.8 | 1.9% | Jan 25, 2022 | The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbi... |
| CVE-2021-45844 | HIGH | 7.8 | 1.1% | Jan 25, 2022 | Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands... |
| CVE-2021-45803 | HIGH | 8.8 | 1.2% | Jan 25, 2022 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is ... |
| CVE-2021-45342 | HIGH | 7.8 | 1.9% | Jan 25, 2022 | A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ... |
| CVE-2021-45341 | HIGH | 8.8 | 6.6% | Jan 25, 2022 | A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ... |
| CVE-2021-46483 | HIGH | 7.8 | 0.8% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c. |
| CVE-2021-46482 | HIGH | 7.8 | 0.8% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c. |
| CVE-2021-44988 | HIGH | 7.8 | 1.1% | Jan 25, 2022 | Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c. |
| CVE-2021-45222 | HIGH | 8.8 | 1.5% | Jan 24, 2022 | An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is... |
| CVE-2021-43588 | HIGH | 7.5 | 1.2% | Jan 24, 2022 | Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthentica... |
| CVE-2021-4088 | HIGH | 7.2 | 2.3% | Jan 24, 2022 | SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.1... |
| CVE-2021-44981 | HIGH | 8.8 | 3.7% | Jan 24, 2022 | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it int... |
| CVE-2021-25076 | HIGH | 8.8 | 19.0% | Jan 24, 2022 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in... |
| CVE-2021-25073 | HIGH | 8.8 | 0.7% | Jan 24, 2022 | The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, al... |
| CVE-2021-25045 | HIGH | 7.2 | 1.5% | Jan 24, 2022 | The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in ... |
| CVE-2021-24936 | HIGH | 8 | 0.5% | Jan 24, 2022 | The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise an... |
| CVE-2021-24906 | HIGH | 7.5 | 1.5% | Jan 24, 2022 | The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, ... |
| CVE-2021-24865 | HIGH | 7.2 | 1.5% | Jan 24, 2022 | The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters ... |
| CVE-2021-24858 | HIGH | 7.2 | 1.3% | Jan 24, 2022 | The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before... |
| CVE-2021-24696 | HIGH | 8.8 | 0.6% | Jan 24, 2022 | The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to ... |
| CVE-2021-39293 | HIGH | 7.5 | 6.9% | Jan 24, 2022 | In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many fil... |
| CVE-2021-39480 | HIGH | 7.5 | 1.1% | Jan 21, 2022 | Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS). |
| CVE-2021-46242 | HIGH | 8.8 | 1.2% | Jan 21, 2022 | HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry. |
| CVE-2021-36339 | HIGH | 7.8 | 0.2% | Jan 21, 2022 | The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentiall... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now