2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25066 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing hi... |
| CVE-2021-25056 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high pri... |
| CVE-2021-37524 | MEDIUM | 6.1 | 0.7% | Jul 1, 2022 | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web... |
| CVE-2021-32428 | CRITICAL | 9.8 | 1.0% | Jul 1, 2022 | SQL Injection vulnerability in viaviwebtech Android EBook App (Books App, PDF, ePub, Online Book Reading, Download Books... |
| CVE-2021-41995 | HIGH | 7.5 | 0.7% | Jun 30, 2022 | A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to ... |
| CVE-2021-38954 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitiv... |
| CVE-2021-38941 | HIGH | 8.1 | 0.8% | Jun 30, 2022 | IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable t... |
| CVE-2021-37791 | MEDIUM | 4.9 | 0.7% | Jun 30, 2022 | MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?u... |
| CVE-2021-37778 | CRITICAL | 9.8 | 1.3% | Jun 30, 2022 | There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code ... |
| CVE-2021-37770 | HIGH | 7.2 | 1.1% | Jun 30, 2022 | Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upl... |
| CVE-2021-41506 | CRITICAL | 9.8 | 1.8% | Jun 30, 2022 | Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, HI351... |
| CVE-2021-40663 | CRITICAL | 9.8 | 1.4% | Jun 30, 2022 | deep.assign npm package 0.0.0-alpha.0 is vulnerable to Improperly Controlled Modification of Object Prototype Attributes... |
| CVE-2021-40643 | CRITICAL | 9.8 | 2.2% | Jun 30, 2022 | EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the... |
| CVE-2021-40597 | CRITICAL | 9.8 | 1.5% | Jun 29, 2022 | The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password. |
| CVE-2021-39074 | MEDIUM | 6.1 | 0.5% | Jun 29, 2022 | IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2021-40642 | MEDIUM | 4.3 | 0.4% | Jun 29, 2022 | Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribu... |
| CVE-2021-41559 | MEDIUM | 6.5 | 1.0% | Jun 28, 2022 | Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack vi... |
| CVE-2021-3435 | LOW | 3.3 | 0.2% | Jun 28, 2022 | Information leakage in le_ecred_conn_req(). Zephyr versions >= v2.4.0 Use of Uninitialized Resource (CWE-908). For more ... |
| CVE-2021-3434 | HIGH | 7.8 | 0.2% | Jun 28, 2022 | Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For... |
| CVE-2021-3433 | LOW | 3.3 | 0.2% | Jun 28, 2022 | Invalid channel map in CONNECT_IND results to Deadlock. Zephyr versions >= v2.5.0 Improper Check or Handling of Exceptio... |
| CVE-2021-3432 | HIGH | 7.5 | 0.8% | Jun 28, 2022 | Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more... |
| CVE-2021-3431 | HIGH | 7.5 | 0.8% | Jun 28, 2022 | Assertion reachable with repeated LL_FEATURE_REQ. Zephyr versions >= v2.5.0 contain Reachable Assertion (CWE-617). For m... |
| CVE-2021-3430 | HIGH | 7.5 | 0.8% | Jun 28, 2022 | Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617... |
| CVE-2021-40553 | HIGH | 8.8 | 2.2% | Jun 28, 2022 | piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor. |
| CVE-2021-3779 | MEDIUM | 6.5 | 1.1% | Jun 28, 2022 | A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without e... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now