2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32842 | MEDIUM | 5.3 | 0.9% | Jan 26, 2022 | SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a che... |
| CVE-2021-29838 | MEDIUM | 5.9 | 1.3% | Jan 26, 2022 | IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2021-44692 | MEDIUM | 5.3 | 1.1% | Jan 26, 2022 | BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new u... |
| CVE-2021-43334 | MEDIUM | 5.4 | 0.6% | Jan 26, 2022 | BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field. |
| CVE-2021-22570 | MEDIUM | 5.5 | 2.7% | Jan 26, 2022 | Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unche... |
| CVE-2021-44120 | MEDIUM | 5.4 | 0.6% | Jan 26, 2022 | SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the functio... |
| CVE-2021-44118 | MEDIUM | 5.4 | 0.8% | Jan 26, 2022 | SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must brows... |
| CVE-2021-36346 | MEDIUM | 5.3 | 4.2% | Jan 25, 2022 | Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker c... |
| CVE-2021-4145 | MEDIUM | 6.5 | 0.4% | Jan 25, 2022 | A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` poin... |
| CVE-2021-45729 | MEDIUM | 5.4 | 0.7% | Jan 25, 2022 | The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe... |
| CVE-2021-40337 | MEDIUM | 5.4 | 0.4% | Jan 25, 2022 | Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulner... |
| CVE-2021-46087 | MEDIUM | 5.4 | 0.5% | Jan 25, 2022 | In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not ... |
| CVE-2021-46085 | MEDIUM | 6.5 | 0.7% | Jan 25, 2022 | OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators be... |
| CVE-2021-46084 | MEDIUM | 5.4 | 0.4% | Jan 25, 2022 | uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box. |
| CVE-2021-46083 | MEDIUM | 5.4 | 0.4% | Jan 25, 2022 | uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code. |
| CVE-2021-46034 | MEDIUM | 6.1 | 0.6% | Jan 25, 2022 | A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickn... |
| CVE-2021-34870 | MEDIUM | 6.5 | 0.9% | Jan 25, 2022 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG... |
| CVE-2021-45847 | MEDIUM | 5.5 | 0.8% | Jan 25, 2022 | Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to ca... |
| CVE-2021-45846 | MEDIUM | 5.5 | 0.6% | Jan 25, 2022 | A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF ... |
| CVE-2021-45343 | MEDIUM | 5.5 | 0.9% | Jan 25, 2022 | In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the applicat... |
| CVE-2021-45340 | MEDIUM | 6.5 | 0.9% | Jan 25, 2022 | In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows a... |
| CVE-2021-46481 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c. |
| CVE-2021-46480 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability... |
| CVE-2021-46478 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiClearStack in src/jsiEval.c. This vulnerability can... |
| CVE-2021-46477 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via RegExp_constructor in src/jsiRegexp.c. This vulnerabil... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now