2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24912 | MEDIUM | 5.4 | 0.3% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX ac... |
| CVE-2021-24911 | MEDIUM | 5.4 | 0.6% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from th... |
| CVE-2021-24910 | MEDIUM | 6.1 | 1.3% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJ... |
| CVE-2021-44545 | MEDIUM | 6.5 | 0.5% | Aug 18, 2022 | Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticat... |
| CVE-2021-44470 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authentic... |
| CVE-2021-37409 | HIGH | 7.8 | 0.2% | Aug 18, 2022 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user ... |
| CVE-2021-33847 | HIGH | 7.8 | 0.2% | Aug 18, 2022 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products be... |
| CVE-2021-33128 | MEDIUM | 4.4 | 0.2% | Aug 18, 2022 | Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.0.6 may allow a p... |
| CVE-2021-33126 | MEDIUM | 4.4 | 0.2% | Aug 18, 2022 | Improper access control in the firmware for some Intel(R) 700 and 722 Series Ethernet Controllers and Adapters before ve... |
| CVE-2021-33060 | HIGH | 7.8 | 0.3% | Aug 18, 2022 | Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially ena... |
| CVE-2021-26950 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi... |
| CVE-2021-26257 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products be... |
| CVE-2021-26254 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to po... |
| CVE-2021-23223 | HIGH | 7.8 | 0.3% | Aug 18, 2022 | Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user ... |
| CVE-2021-23188 | LOW | 3.3 | 0.2% | Aug 18, 2022 | Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated u... |
| CVE-2021-23179 | HIGH | 7.1 | 0.2% | Aug 18, 2022 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi... |
| CVE-2021-23168 | MEDIUM | 6.5 | 0.3% | Aug 18, 2022 | Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user... |
| CVE-2021-32862 | MEDIUM | 5.4 | 1.1% | Aug 18, 2022 | The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using... |
| CVE-2021-30071 | MEDIUM | 6.1 | 0.5% | Aug 18, 2022 | A cross-site scripting (XSS) vulnerability in /admin/list_key.html of HestiaCP before v1.3.5 allows attackers to execute... |
| CVE-2021-30070 | HIGH | 7.5 | 0.6% | Aug 18, 2022 | An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values take... |
| CVE-2021-26639 | HIGH | 7.5 | 0.4% | Aug 17, 2022 | This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Re... |
| CVE-2021-45454 | HIGH | 7.5 | 0.6% | Aug 17, 2022 | Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 allow information disclosure of power telemetry via HWmon. |
| CVE-2021-42052 | HIGH | 7.5 | 0.9% | Aug 16, 2022 | IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEReso... |
| CVE-2021-39087 | MEDIUM | 6.5 | 0.5% | Aug 16, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1... |
| CVE-2021-39086 | MEDIUM | 5.3 | 0.8% | Aug 16, 2022 | IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a re... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now