2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4282 | MEDIUM | 6.1 | 0.5% | Dec 27, 2022 | A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is a... |
| CVE-2021-4281 | CRITICAL | 9.8 | 1.8% | Dec 26, 2022 | A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown f... |
| CVE-2021-24942 | HIGH | 7.2 | 1.2% | Dec 26, 2022 | The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" optio... |
| CVE-2021-35065 | HIGH | 7.5 | 1.6% | Dec 26, 2022 | The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the... |
| CVE-2021-30134 | MEDIUM | 6.1 | 1.3% | Dec 26, 2022 | php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key paramet... |
| CVE-2021-44856 | MEDIUM | 5.3 | 0.5% | Dec 26, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by A... |
| CVE-2021-43395 | MEDIUM | 5.5 | 0.3% | Dec 26, 2022 | An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, Op... |
| CVE-2021-39369 | MEDIUM | 6.5 | 0.9% | Dec 26, 2022 | In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by auth... |
| CVE-2021-38561 | HIGH | 7.5 | 1.4% | Dec 26, 2022 | golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language... |
| CVE-2021-35954 | HIGH | 8.1 | 0.3% | Dec 26, 2022 | fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, fla... |
| CVE-2021-35953 | HIGH | 7.5 | 0.8% | Dec 26, 2022 | fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device o... |
| CVE-2021-35952 | MEDIUM | 5.3 | 0.6% | Dec 26, 2022 | fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month vi... |
| CVE-2021-35951 | HIGH | 7.5 | 0.9% | Dec 26, 2022 | fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious f... |
| CVE-2021-45467 | CRITICAL | 9.8 | 70.9% | Dec 26, 2022 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c... |
| CVE-2021-45466 | CRITICAL | 9.8 | 55.3% | Dec 26, 2022 | In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=a... |
| CVE-2021-44855 | MEDIUM | 5.4 | 0.6% | Dec 26, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Store... |
| CVE-2021-44854 | MEDIUM | 5.3 | 0.6% | Dec 26, 2022 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicl... |
| CVE-2021-44758 | HIGH | 7.5 | 1.2% | Dec 26, 2022 | Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type... |
| CVE-2021-4280 | MEDIUM | 6.5 | 0.7% | Dec 25, 2022 | A vulnerability was found in styler_praat_scripts. It has been classified as problematic. Affected is an unknown functio... |
| CVE-2021-4279 | CRITICAL | 9.8 | 1.1% | Dec 25, 2022 | A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerabil... |
| CVE-2021-4278 | HIGH | 7.8 | 0.4% | Dec 25, 2022 | A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. ... |
| CVE-2021-4277 | MEDIUM | 5.3 | 0.5% | Dec 25, 2022 | A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown... |
| CVE-2021-4276 | HIGH | 8.8 | 0.6% | Dec 25, 2022 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affec... |
| CVE-2021-32692 | CRITICAL | 9.6 | 0.7% | Dec 23, 2022 | Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute a... |
| CVE-2021-4221 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This coul... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now