2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36341 | MEDIUM | 5.5 | 0.2% | Dec 21, 2021 | Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated... |
| CVE-2021-36318 | MEDIUM | 6.7 | 0.2% | Dec 21, 2021 | Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged... |
| CVE-2021-36317 | MEDIUM | 6.7 | 0.2% | Dec 21, 2021 | Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacke... |
| CVE-2021-45091 | MEDIUM | 4.3 | 0.6% | Dec 21, 2021 | Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control. |
| CVE-2021-45089 | MEDIUM | 5.2 | 0.3% | Dec 21, 2021 | Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control. |
| CVE-2021-24956 | MEDIUM | 6.1 | 1.7% | Dec 21, 2021 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sSh... |
| CVE-2021-24941 | MEDIUM | 6.1 | 0.8% | Dec 21, 2021 | The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape th... |
| CVE-2021-24907 | MEDIUM | 6.1 | 0.9% | Dec 21, 2021 | The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter befo... |
| CVE-2021-24738 | MEDIUM | 5.4 | 0.6% | Dec 21, 2021 | The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which co... |
| CVE-2021-24578 | MEDIUM | 6.1 | 0.8% | Dec 21, 2021 | The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting bac... |
| CVE-2021-43842 | MEDIUM | 5.4 | 0.7% | Dec 20, 2021 | Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripti... |
| CVE-2021-43847 | MEDIUM | 6.5 | 1.2% | Dec 20, 2021 | HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possibl... |
| CVE-2021-43846 | MEDIUM | 4.3 | 0.6% | Dec 20, 2021 | `solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior t... |
| CVE-2021-43750 | MEDIUM | 5.5 | 1.4% | Dec 20, 2021 | Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthent... |
| CVE-2021-43749 | MEDIUM | 5.5 | 1.4% | Dec 20, 2021 | Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthent... |
| CVE-2021-43748 | MEDIUM | 5.5 | 1.4% | Dec 20, 2021 | Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthent... |
| CVE-2021-43746 | MEDIUM | 5.5 | 1.7% | Dec 20, 2021 | Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows re... |
| CVE-2021-42808 | MEDIUM | 6.7 | 0.2% | Dec 20, 2021 | Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. |
| CVE-2021-42138 | MEDIUM | 6.5 | 0.6% | Dec 20, 2021 | A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted crede... |
| CVE-2021-36889 | MEDIUM | 4.8 | 0.6% | Dec 20, 2021 | Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies l... |
| CVE-2021-35248 | MEDIUM | 4.3 | 0.9% | Dec 20, 2021 | It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate user... |
| CVE-2021-43441 | MEDIUM | 5.3 | 1.2% | Dec 20, 2021 | An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup ... |
| CVE-2021-43440 | MEDIUM | 6.1 | 1.4% | Dec 20, 2021 | Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code vi... |
| CVE-2021-43438 | MEDIUM | 5.4 | 0.7% | Dec 20, 2021 | Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field |
| CVE-2021-44916 | MEDIUM | 6.1 | 3.7% | Dec 20, 2021 | Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now