2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33087 | MEDIUM | 5.5 | 0.2% | Nov 17, 2021 | Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before versio... |
| CVE-2021-33086 | MEDIUM | 5.5 | 0.2% | Nov 17, 2021 | Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of s... |
| CVE-2021-42360 | MEDIUM | 5.4 | 0.6% | Nov 17, 2021 | On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab... |
| CVE-2021-33480 | MEDIUM | 5.5 | 1.0% | Nov 17, 2021 | An use-after-free vulnerability was discovered in gocr through 0.53-20200802 in context_correction() in pgm2asc.c. |
| CVE-2021-43977 | MEDIUM | 6.1 | 0.6% | Nov 17, 2021 | SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS. |
| CVE-2021-43976 | MEDIUM | 4.6 | 0.6% | Nov 17, 2021 | In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (w... |
| CVE-2021-43975 | MEDIUM | 6.7 | 0.5% | Nov 17, 2021 | In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_uti... |
| CVE-2021-42250 | MEDIUM | 6.5 | 1.8% | Nov 17, 2021 | Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to f... |
| CVE-2021-38959 | MEDIUM | 5.5 | 0.2% | Nov 17, 2021 | IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of s... |
| CVE-2021-29861 | MEDIUM | 6.2 | 0.3% | Nov 17, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensi... |
| CVE-2021-29860 | MEDIUM | 6.2 | 0.3% | Nov 17, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library ... |
| CVE-2021-24856 | MEDIUM | 4.8 | 0.6% | Nov 17, 2021 | The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c... |
| CVE-2021-24854 | MEDIUM | 5.4 | 0.6% | Nov 17, 2021 | The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could... |
| CVE-2021-24853 | MEDIUM | 4.3 | 0.4% | Nov 17, 2021 | The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector se... |
| CVE-2021-24852 | MEDIUM | 6.5 | 0.5% | Nov 17, 2021 | The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which c... |
| CVE-2021-24851 | MEDIUM | 4.3 | 0.9% | Nov 17, 2021 | The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta... |
| CVE-2021-24850 | MEDIUM | 5.4 | 0.6% | Nov 17, 2021 | The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. ... |
| CVE-2021-24841 | MEDIUM | 4.8 | 0.7% | Nov 17, 2021 | The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2021-24834 | MEDIUM | 5.4 | 1.5% | Nov 17, 2021 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in th... |
| CVE-2021-24833 | MEDIUM | 5.4 | 1.1% | Nov 17, 2021 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in t... |
| CVE-2021-24815 | MEDIUM | 4.8 | 0.6% | Nov 17, 2021 | The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But... |
| CVE-2021-24802 | MEDIUM | 6.5 | 0.5% | Nov 17, 2021 | The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make... |
| CVE-2021-24796 | MEDIUM | 6.1 | 1.2% | Nov 17, 2021 | The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets be... |
| CVE-2021-24787 | MEDIUM | 4.8 | 0.6% | Nov 17, 2021 | The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings... |
| CVE-2021-24776 | MEDIUM | 4.3 | 0.4% | Nov 17, 2021 | The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which co... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now