2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31885 | HIGH | 7.5 | 1.2% | Nov 9, 2021 | A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver... |
| CVE-2021-31883 | HIGH | 7.5 | 1.5% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-31882 | HIGH | 7.5 | 1.5% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-31881 | HIGH | 7.5 | 1.5% | Nov 9, 2021 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R... |
| CVE-2021-41253 | HIGH | 8.1 | 1.8% | Nov 8, 2021 | Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions prov... |
| CVE-2021-24844 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL s... |
| CVE-2021-24835 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before... |
| CVE-2021-24829 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to t... |
| CVE-2021-24791 | HIGH | 7.2 | 5.0% | Nov 8, 2021 | The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" req... |
| CVE-2021-24695 | HIGH | 7.5 | 1.6% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any au... |
| CVE-2021-24669 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter... |
| CVE-2021-24647 | HIGH | 8.1 | 8.4% | Nov 8, 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres... |
| CVE-2021-24631 | HIGH | 8.8 | 1.5% | Nov 8, 2021 | The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in... |
| CVE-2021-24630 | HIGH | 8.8 | 1.5% | Nov 8, 2021 | The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQ... |
| CVE-2021-24629 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before usi... |
| CVE-2021-24628 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL ... |
| CVE-2021-24627 | HIGH | 7.2 | 6.6% | Nov 8, 2021 | The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in... |
| CVE-2021-24626 | HIGH | 8.8 | 0.7% | Nov 8, 2021 | The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allow... |
| CVE-2021-24625 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from... |
| CVE-2021-24575 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared s... |
| CVE-2021-24537 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened... |
| CVE-2021-39182 | HIGH | 7.5 | 0.5% | Nov 8, 2021 | EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorith... |
| CVE-2021-28022 | HIGH | 7.5 | 1.1% | Nov 8, 2021 | Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate inform... |
| CVE-2021-41772 | HIGH | 7.5 | 3.1% | Nov 8, 2021 | Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing ... |
| CVE-2021-41771 | HIGH | 7.5 | 4.4% | Nov 8, 2021 | ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Loc... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now