2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20872 | MEDIUM | 6.8 | 0.3% | Jan 4, 2022 | Protection mechanism failure vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650... |
| CVE-2021-20871 | MEDIUM | 6.5 | 0.5% | Jan 4, 2022 | Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G... |
| CVE-2021-20870 | MEDIUM | 4.6 | 0.3% | Jan 4, 2022 | Improper handling of exceptional conditions vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earli... |
| CVE-2021-20869 | MEDIUM | 6.5 | 0.5% | Jan 4, 2022 | Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G... |
| CVE-2021-20868 | MEDIUM | 4.5 | 0.4% | Jan 4, 2022 | Incorrect authorization vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C55... |
| CVE-2021-43942 | MEDIUM | 6.1 | 55.4% | Jan 4, 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2021-45829 | MEDIUM | 5.5 | 0.7% | Jan 3, 2022 | HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service. |
| CVE-2021-39981 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | Chang Lian application has a vulnerability which can be maliciously exploited to hide the calling number.Successful expl... |
| CVE-2021-39980 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploita... |
| CVE-2021-37132 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this ... |
| CVE-2021-37118 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | The HwNearbyMain module has a Improper Handling of Exceptional Conditions vulnerability.Successful exploitation of this ... |
| CVE-2021-37114 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | There is an Out-of-bounds read vulnerability in Smartphone.Successful exploitation of this vulnerability may affect serv... |
| CVE-2021-37112 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this v... |
| CVE-2021-20148 | MEDIUM | 4.3 | 1.1% | Jan 3, 2022 | ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web roo... |
| CVE-2021-20147 | MEDIUM | 5.3 | 6.9% | Jan 3, 2022 | ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of th... |
| CVE-2021-46109 | MEDIUM | 6.1 | 0.7% | Jan 3, 2022 | Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to... |
| CVE-2021-3837 | MEDIUM | 6.1 | 0.5% | Jan 3, 2022 | openwhyd is vulnerable to Improper Authorization |
| CVE-2021-44674 | MEDIUM | 6.5 | 1.3% | Jan 3, 2022 | An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticate... |
| CVE-2021-25040 | MEDIUM | 6.1 | 0.8% | Jan 3, 2022 | The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before output... |
| CVE-2021-25027 | MEDIUM | 6.1 | 0.9% | Jan 3, 2022 | The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it ... |
| CVE-2021-25022 | MEDIUM | 6.1 | 1.1% | Jan 3, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestam... |
| CVE-2021-25021 | MEDIUM | 4.9 | 1.0% | Jan 3, 2022 | The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allow... |
| CVE-2021-25020 | MEDIUM | 4.9 | 1.0% | Jan 3, 2022 | The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, al... |
| CVE-2021-25016 | MEDIUM | 6.1 | 1.8% | Jan 3, 2022 | The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the searc... |
| CVE-2021-25001 | MEDIUM | 6.1 | 0.8% | Jan 3, 2022 | The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_resul... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now