2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4282MEDIUM6.1A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is a...
CVE-2021-4281CRITICAL9.8A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown f...
CVE-2021-24942HIGH7.2The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" optio...
CVE-2021-35065HIGH7.5The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the...
CVE-2021-30134MEDIUM6.1php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key paramet...
CVE-2021-44856MEDIUM5.3An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A title blocked by A...
CVE-2021-43395MEDIUM5.5An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, Op...
CVE-2021-39369MEDIUM6.5In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by auth...
CVE-2021-38561HIGH7.5golang.org/x/text/language in golang.org/x/text before 0.3.7 can panic with an out-of-bounds read during BCP 47 language...
CVE-2021-35954HIGH8.1fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows physically proximate attackers to dump the firmware, fla...
CVE-2021-35953HIGH7.5fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to cause a Denial of Service (device o...
CVE-2021-35952MEDIUM5.3fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows a Remote attacker to change the time, date, and month vi...
CVE-2021-35951HIGH7.5fastrack Reflex 2.0 W307S_REFLEX_v90.89 Activity Tracker allows an Unauthenticated Remote attacker to send a malicious f...
CVE-2021-45467CRITICAL9.8In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to c...
CVE-2021-45466CRITICAL9.8In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=a...
CVE-2021-44855MEDIUM5.4An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. There is Blind Store...
CVE-2021-44854MEDIUM5.3An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicl...
CVE-2021-44758HIGH7.5Heimdal before 7.7.1 allows attackers to cause a NULL pointer dereference in a SPNEGO acceptor via a preferred_mech_type...
CVE-2021-4280MEDIUM6.5A vulnerability was found in styler_praat_scripts. It has been classified as problematic. Affected is an unknown functio...
CVE-2021-4279CRITICAL9.8A vulnerability has been found in Starcounter-Jack JSON-Patch up to 3.1.0 and classified as problematic. This vulnerabil...
CVE-2021-4278HIGH7.8A vulnerability classified as problematic has been found in cronvel tree-kit up to 0.6.x. This affects an unknown part. ...
CVE-2021-4277MEDIUM5.3A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown...
CVE-2021-4276HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in dns-stats hedgehog. It has been rated as problematic. Affec...
CVE-2021-32692CRITICAL9.6Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute a...
CVE-2021-4221MEDIUM4.3If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This coul...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now