2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36843 | MEDIUM | 4.8 | 0.6% | Nov 26, 2021 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin ... |
| CVE-2021-25269 | MEDIUM | 4.4 | 0.2% | Nov 26, 2021 | A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service p... |
| CVE-2021-44225 | MEDIUM | 5.4 | 1.2% | Nov 26, 2021 | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user ... |
| CVE-2021-41270 | MEDIUM | 6.5 | 1.4% | Nov 24, 2021 | Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and consol... |
| CVE-2021-41267 | MEDIUM | 6.5 | 1.2% | Nov 24, 2021 | Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set... |
| CVE-2021-43268 | MEDIUM | 6.5 | 0.8% | Nov 24, 2021 | An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to readin... |
| CVE-2021-43777 | MEDIUM | 6.1 | 0.3% | Nov 24, 2021 | Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google L... |
| CVE-2021-41192 | MEDIUM | 6.5 | 8.0% | Nov 24, 2021 | Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without exp... |
| CVE-2021-32037 | MEDIUM | 6.5 | 1.2% | Nov 24, 2021 | An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregati... |
| CVE-2021-20848 | MEDIUM | 6.1 | 0.9% | Nov 24, 2021 | Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary scr... |
| CVE-2021-20844 | MEDIUM | 5.7 | 0.9% | Nov 24, 2021 | Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17... |
| CVE-2021-20843 | MEDIUM | 5.4 | 0.7% | Nov 24, 2021 | Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and ear... |
| CVE-2021-20842 | MEDIUM | 6.5 | 0.5% | Nov 24, 2021 | Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack ... |
| CVE-2021-20841 | MEDIUM | 6.5 | 1.3% | Nov 24, 2021 | Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker... |
| CVE-2021-20840 | MEDIUM | 6.1 | 1.2% | Nov 24, 2021 | Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 all... |
| CVE-2021-40369 | MEDIUM | 6.1 | 3.3% | Nov 24, 2021 | A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce... |
| CVE-2021-43221 | MEDIUM | 4.2 | 1.0% | Nov 24, 2021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2021-43211 | MEDIUM | 5.5 | 0.7% | Nov 24, 2021 | Windows 10 Update Assistant Elevation of Privilege Vulnerability |
| CVE-2021-42297 | MEDIUM | 5 | 1.5% | Nov 24, 2021 | Windows 10 Update Assistant Elevation of Privilege Vulnerability |
| CVE-2021-38004 | MEDIUM | 4.3 | 0.8% | Nov 23, 2021 | Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cro... |
| CVE-2021-38000 | MEDIUM | 6.1 | 4.5% | Nov 23, 2021 | Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote... |
| CVE-2021-37999 | MEDIUM | 6.1 | 0.9% | Nov 23, 2021 | Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject ... |
| CVE-2021-38980 | MEDIUM | 5.3 | 1.2% | Nov 23, 2021 | IBM Tivoli Key Lifecycle Manager (IBM Security Guardium Key Lifecycle Manager) 3.0, 3.0.1, 4.0, and 4.1 could allow a re... |
| CVE-2021-38875 | MEDIUM | 6.5 | 1.0% | Nov 23, 2021 | IBM MQ 8.0, 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.1 CD, and 9.2 CD is vulnerable to a denial of service attack caused by an error... |
| CVE-2021-36334 | MEDIUM | 6.8 | 0.7% | Nov 23, 2021 | Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A remote high privileged at... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now