2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3026 | MEDIUM | 6.1 | 0.6% | Jan 5, 2021 | Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment. |
| CVE-2021-3022 | MEDIUM | 5.5 | 0.1% | Jan 5, 2021 | An issue was discovered on LG mobile devices with Android OS 10 software. There was no write protection for the MTK prot... |
| CVE-2021-22495 | MEDIUM | 5.5 | 0.3% | Jan 5, 2021 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) (Exynos chipsets) software. ... |
| CVE-2021-22494 | MEDIUM | 5.5 | 0.3% | Jan 5, 2021 | An issue was discovered in the fingerprint scanner on Samsung Note20 mobile devices with Q(10.0) software. When a screen... |
| CVE-2021-22493 | — | — | — | Jan 5, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-25346. Reason: This candidate is a duplicate of ... |
| CVE-2021-22492 | HIGH | 8.8 | 0.3% | Jan 5, 2021 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Broadcom Bluetooth chipsets) softwar... |
| CVE-2021-21234 | HIGH | 7.7 | 21.2% | Jan 5, 2021 | spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is mave... |
| CVE-2021-3021 | CRITICAL | 9.8 | 2.1% | Jan 5, 2021 | ISPConfig before 3.2.2 allows SQL injection. |
| CVE-2021-3019 | HIGH | 7.5 | 19.0% | Jan 5, 2021 | ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection t... |
| CVE-2021-3018 | CRITICAL | 9.8 | 19.5% | Jan 5, 2021 | ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the ... |
| CVE-2021-3014 | MEDIUM | 6.1 | 0.9% | Jan 4, 2021 | In MikroTik RouterOS through 2021-01-04, the hotspot login page is vulnerable to reflected XSS via the target parameter. |
| CVE-2021-3007 | CRITICAL | 9.8 | 75.3% | Jan 4, 2021 | Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead ... |
| CVE-2021-21495 | HIGH | 8.8 | 0.5% | Jan 4, 2021 | MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI... |
| CVE-2021-21494 | MEDIUM | 4.8 | 0.5% | Jan 4, 2021 | MK-AUTH through 19.01 K4.9 allows XSS via the admin/logs_ajax.php tipo parameter. An attacker can leverage this to read ... |
| CVE-2021-3006 | HIGH | 7.5 | 1.3% | Jan 3, 2021 | The breed function in the smart contract implementation for Farm in Seal Finance (Seal), an Ethereum token, lacks access... |
| CVE-2021-3005 | MEDIUM | 4.3 | 0.9% | Jan 3, 2021 | MK-AUTH through 19.01 K4.9 allows remote attackers to obtain sensitive information (e.g., a CPF number) via a modified t... |
| CVE-2021-3004 | HIGH | 7.5 | 1.3% | Jan 3, 2021 | The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has cer... |
| CVE-2021-3002 | MEDIUM | 6.1 | 4.3% | Jan 1, 2021 | Seo Panel 4.8.0 allows reflected XSS via the seo/seopanel/login.php?sec=forgot email parameter. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now