2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42358 | HIGH | 8.8 | 0.6% | Nov 29, 2021 | The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validati... |
| CVE-2021-24889 | HIGH | 7.2 | 1.3% | Nov 29, 2021 | The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which coul... |
| CVE-2021-24860 | HIGH | 7.2 | 1.3% | Nov 29, 2021 | The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before u... |
| CVE-2021-24755 | HIGH | 8.8 | 1.3% | Nov 29, 2021 | The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL stateme... |
| CVE-2021-24748 | HIGH | 8.8 | 1.3% | Nov 29, 2021 | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET pa... |
| CVE-2021-38283 | HIGH | 7.5 | 2.4% | Nov 29, 2021 | Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing se... |
| CVE-2021-38147 | HIGH | 7.5 | 53.0% | Nov 29, 2021 | Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as report... |
| CVE-2021-44094 | HIGH | 7.8 | 1.4% | Nov 28, 2021 | ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file |
| CVE-2021-41279 | HIGH | 8.8 | 1.6% | Nov 26, 2021 | BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions use... |
| CVE-2021-41243 | HIGH | 8.8 | 2.2% | Nov 26, 2021 | There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS.... |
| CVE-2021-35533 | HIGH | 7.5 | 0.9% | Nov 26, 2021 | Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-... |
| CVE-2021-26615 | HIGH | 8.8 | 0.6% | Nov 26, 2021 | ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW functi... |
| CVE-2021-36807 | HIGH | 8.8 | 1.5% | Nov 26, 2021 | An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before versi... |
| CVE-2021-38686 | HIGH | 8.8 | 0.9% | Nov 26, 2021 | An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerabil... |
| CVE-2021-43778 | HIGH | 7.5 | 52.7% | Nov 24, 2021 | Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the ... |
| CVE-2021-41268 | HIGH | 8.8 | 1.3% | Nov 24, 2021 | Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of... |
| CVE-2021-22957 | HIGH | 8.8 | 0.9% | Nov 24, 2021 | A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allow... |
| CVE-2021-38873 | HIGH | 7.8 | 1.8% | Nov 24, 2021 | IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary command... |
| CVE-2021-36917 | HIGH | 7.5 | 1.9% | Nov 24, 2021 | WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie... |
| CVE-2021-34424 | HIGH | 7.5 | 1.7% | Nov 24, 2021 | A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before vers... |
| CVE-2021-21980 | HIGH | 7.5 | 4.6% | Nov 24, 2021 | The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n... |
| CVE-2021-43780 | HIGH | 8.8 | 1.0% | Nov 24, 2021 | Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading da... |
| CVE-2021-3553 | HIGH | 7.5 | 1.3% | Nov 24, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows... |
| CVE-2021-3552 | HIGH | 7.5 | 1.4% | Nov 24, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To... |
| CVE-2021-31822 | HIGH | 7.8 | 0.2% | Nov 24, 2021 | When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now