2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46422 | CRITICAL | 9.8 | 94.8% | Apr 27, 2022 | Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute... |
| CVE-2021-46442 | CRITICAL | 9.8 | 54.6% | Apr 27, 2022 | In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", a... |
| CVE-2021-46441 | HIGH | 8.8 | 31.8% | Apr 27, 2022 | In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" para... |
| CVE-2021-46421 | HIGH | 7.5 | 5.7% | Apr 27, 2022 | Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, w... |
| CVE-2021-46420 | HIGH | 7.5 | 5.5% | Apr 27, 2022 | Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability,... |
| CVE-2021-41041 | MEDIUM | 5.3 | 1.0% | Apr 27, 2022 | In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification w... |
| CVE-2021-36895 | MEDIUM | 6.1 | 0.7% | Apr 26, 2022 | Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG ima... |
| CVE-2021-36867 | MEDIUM | 5.4 | 0.5% | Apr 26, 2022 | Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19... |
| CVE-2021-26629 | HIGH | 8.8 | 1.5% | Apr 26, 2022 | A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .... |
| CVE-2021-26628 | MEDIUM | 6.1 | 0.7% | Apr 26, 2022 | Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges.... |
| CVE-2021-35250 | HIGH | 7.5 | 14.4% | Apr 25, 2022 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to t... |
| CVE-2021-4225 | HIGH | 8.8 | 1.7% | Apr 25, 2022 | The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u... |
| CVE-2021-46782 | MEDIUM | 6.1 | 0.8% | Apr 25, 2022 | The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back... |
| CVE-2021-46781 | MEDIUM | 6.1 | 0.8% | Apr 25, 2022 | The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputt... |
| CVE-2021-46780 | MEDIUM | 6.1 | 0.8% | Apr 25, 2022 | The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an at... |
| CVE-2021-39040 | HIGH | 8 | 0.7% | Apr 25, 2022 | IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or si... |
| CVE-2021-25111 | MEDIUM | 6.1 | 1.9% | Apr 25, 2022 | The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before ... |
| CVE-2021-25094 | HIGH | 8.1 | 83.5% | Apr 25, 2022 | The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rog... |
| CVE-2021-24957 | HIGH | 8.8 | 1.3% | Apr 25, 2022 | The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a S... |
| CVE-2021-24805 | MEDIUM | 4.3 | 0.4% | Apr 25, 2022 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, a... |
| CVE-2021-24800 | MEDIUM | 4.3 | 0.6% | Apr 25, 2022 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user ... |
| CVE-2021-36460 | HIGH | 7.8 | 0.4% | Apr 25, 2022 | VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authen... |
| CVE-2021-45842 | HIGH | 7.5 | 2.3% | Apr 25, 2022 | It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-210714151... |
| CVE-2021-45841 | HIGH | 8.1 | 8.1% | Apr 25, 2022 | In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta... |
| CVE-2021-45840 | CRITICAL | 9.8 | 3.9% | Apr 25, 2022 | It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now