2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44965 | HIGH | 7.5 | 2.2% | Dec 13, 2021 | Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 Th... |
| CVE-2021-24970 | HIGH | 7.2 | 5.9% | Dec 13, 2021 | The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using... |
| CVE-2021-24945 | HIGH | 8 | 0.6% | Dec 13, 2021 | The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the l... |
| CVE-2021-24861 | HIGH | 7.2 | 1.3% | Dec 13, 2021 | The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using i... |
| CVE-2021-24848 | HIGH | 8.8 | 1.3% | Dec 13, 2021 | The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authentic... |
| CVE-2021-24747 | HIGH | 7.2 | 1.5% | Dec 13, 2021 | The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_a... |
| CVE-2021-20865 | HIGH | 7.5 | 2.5% | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au... |
| CVE-2021-44154 | HIGH | 7.2 | 1.8% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_... |
| CVE-2021-44153 | HIGH | 7.2 | 2.0% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable a... |
| CVE-2021-44151 | HIGH | 7.5 | 2.5% | Dec 13, 2021 | An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessi... |
| CVE-2021-40857 | HIGH | 8.8 | 2.0% | Dec 13, 2021 | Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring. |
| CVE-2021-40856 | HIGH | 7.5 | 51.1% | Dec 13, 2021 | Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring. |
| CVE-2021-41805 | HIGH | 8.8 | 34.8% | Dec 12, 2021 | HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. A... |
| CVE-2021-41242 | HIGH | 8.1 | 1.4% | Dec 10, 2021 | OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 1... |
| CVE-2021-26340 | HIGH | 8.4 | 0.2% | Dec 10, 2021 | A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to fl... |
| CVE-2021-27984 | HIGH | 8.1 | 2.5% | Dec 10, 2021 | In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files. |
| CVE-2021-31745 | HIGH | 7.5 | 1.2% | Dec 10, 2021 | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access ... |
| CVE-2021-37935 | HIGH | 7.5 | 1.4% | Dec 10, 2021 | An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenti... |
| CVE-2021-29214 | HIGH | 7.2 | 1.1% | Dec 10, 2021 | A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administr... |
| CVE-2021-37189 | HIGH | 7.5 | 0.6% | Dec 10, 2021 | An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sen... |
| CVE-2021-37188 | HIGH | 8.8 | 0.5% | Dec 10, 2021 | An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firm... |
| CVE-2021-43803 | HIGH | 7.5 | 44.8% | Dec 10, 2021 | Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to ... |
| CVE-2021-43802 | HIGH | 8.8 | 2.0% | Dec 9, 2021 | Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file th... |
| CVE-2021-43982 | HIGH | 7.8 | 9.6% | Dec 9, 2021 | Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an... |
| CVE-2021-37861 | HIGH | 7.5 | 0.9% | Dec 9, 2021 | Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now