2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36891 | MEDIUM | 4.3 | 0.4% | Jun 15, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows chang... |
| CVE-2021-25261 | HIGH | 7.8 | 0.5% | Jun 15, 2022 | Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker... |
| CVE-2021-43756 | HIGH | 7.8 | 2.0% | Jun 15, 2022 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthe... |
| CVE-2021-43754 | HIGH | 7.8 | 1.5% | Jun 15, 2022 | Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling ... |
| CVE-2021-40776 | MEDIUM | 6.1 | 0.5% | Jun 15, 2022 | Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom... |
| CVE-2021-42732 | HIGH | 7.8 | 1.9% | Jun 15, 2022 | Access of Memory Location After End of Buffer (CWE-788) |
| CVE-2021-40940 | CRITICAL | 9.8 | 1.6% | Jun 15, 2022 | Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability. |
| CVE-2021-40727 | HIGH | 7.8 | 1.3% | Jun 15, 2022 | Access of Memory Location After End of Buffer (CWE-788 |
| CVE-2021-39820 | HIGH | 7.8 | 3.5% | Jun 15, 2022 | Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability... |
| CVE-2021-41672 | MEDIUM | 6.5 | 1.4% | Jun 15, 2022 | PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the adm... |
| CVE-2021-40910 | MEDIUM | 6.1 | 0.6% | Jun 15, 2022 | There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side. |
| CVE-2021-33036 | HIGH | 8.8 | 3.2% | Jun 15, 2022 | In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to ... |
| CVE-2021-39806 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead t... |
| CVE-2021-36901 | MEDIUM | 6.1 | 0.7% | Jun 15, 2022 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin <= 2.17.0 at WordPress. |
| CVE-2021-39691 | HIGH | 7.3 | 0.1% | Jun 15, 2022 | In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This... |
| CVE-2021-41413 | HIGH | 7.8 | 0.8% | Jun 15, 2022 | ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_conve... |
| CVE-2021-40212 | CRITICAL | 9.8 | 1.9% | Jun 15, 2022 | An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, informa... |
| CVE-2021-42675 | CRITICAL | 9.8 | 3.1% | Jun 14, 2022 | Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP fi... |
| CVE-2021-40660 | HIGH | 7.5 | 0.9% | Jun 14, 2022 | An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launc... |
| CVE-2021-40678 | MEDIUM | 5.4 | 0.5% | Jun 14, 2022 | In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=bat... |
| CVE-2021-40658 | MEDIUM | 4.8 | 0.5% | Jun 14, 2022 | Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”. |
| CVE-2021-40633 | HIGH | 8.8 | 1.5% | Jun 14, 2022 | A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of mem... |
| CVE-2021-40650 | MEDIUM | 6.5 | 0.7% | Jun 14, 2022 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set. |
| CVE-2021-40649 | MEDIUM | 6.5 | 0.8% | Jun 14, 2022 | In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set. |
| CVE-2021-40616 | MEDIUM | 6.5 | 0.7% | Jun 14, 2022 | thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account wit... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now