2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24878 | MEDIUM | 6.1 | 1.2% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back i... |
| CVE-2021-24843 | MEDIUM | 6.5 | 0.5% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could all... |
| CVE-2021-43929 | MEDIUM | 5.4 | 0.6% | Feb 7, 2022 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work... |
| CVE-2021-4043 | MEDIUM | 5.5 | 4.8% | Feb 4, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0. |
| CVE-2021-43841 | MEDIUM | 5.4 | 0.9% | Feb 4, 2022 | XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki... |
| CVE-2021-40403 | MEDIUM | 6.3 | 1.1% | Feb 4, 2022 | An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and d... |
| CVE-2021-38130 | MEDIUM | 6.5 | 0.8% | Feb 4, 2022 | A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Rel... |
| CVE-2021-36151 | MEDIUM | 5.5 | 0.4% | Feb 4, 2022 | In Apache Gobblin, the Hadoop token is written to a temp file that is visible to all local users on Unix-like systems. T... |
| CVE-2021-32732 | MEDIUM | 6.5 | 0.9% | Feb 4, 2022 | ### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which userna... |
| CVE-2021-29218 | MEDIUM | 6.7 | 0.2% | Feb 4, 2022 | A local unquoted search path security vulnerability has been identified in HPE Agentless Management Service for Windows ... |
| CVE-2021-21971 | MEDIUM | 5.9 | 0.7% | Feb 4, 2022 | An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1... |
| CVE-2021-21963 | MEDIUM | 5.9 | 0.5% | Feb 4, 2022 | An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W... |
| CVE-2021-46671 | MEDIUM | 5.3 | 1.3% | Feb 4, 2022 | options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data t... |
| CVE-2021-45408 | MEDIUM | 6.1 | 0.6% | Feb 4, 2022 | Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect us... |
| CVE-2021-45429 | MEDIUM | 5.5 | 0.8% | Feb 4, 2022 | A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set... |
| CVE-2021-29398 | MEDIUM | 5.3 | 1.8% | Feb 4, 2022 | Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Cl... |
| CVE-2021-29394 | MEDIUM | 6.5 | 0.8% | Feb 4, 2022 | Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 all... |
| CVE-2021-43635 | MEDIUM | 6.1 | 1.7% | Feb 4, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malic... |
| CVE-2021-44886 | MEDIUM | 5.3 | 0.9% | Feb 4, 2022 | In Zammad 5.0.2, agents can configure "out of office" periods and substitute persons. If the substitute persons didn't h... |
| CVE-2021-44983 | MEDIUM | 4.9 | 1.1% | Feb 4, 2022 | In taocms 3.0.1 after logging in to the background, there is an Arbitrary file download vulnerability at the File Manage... |
| CVE-2021-42059 | MEDIUM | 6.7 | 0.3% | Feb 3, 2022 | An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05... |
| CVE-2021-39021 | MEDIUM | 5.3 | 0.5% | Feb 2, 2022 | IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under different circumstance... |
| CVE-2021-42639 | MEDIUM | 6.1 | 1.2% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulner... |
| CVE-2021-42633 | MEDIUM | 5.3 | 2.0% | Feb 2, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to ... |
| CVE-2021-43062 | MEDIUM | 6.1 | 12.9% | Feb 2, 2022 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now