2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24607 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to... |
| CVE-2021-24594 | MEDIUM | 4.8 | 0.7% | Nov 8, 2021 | The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of... |
| CVE-2021-29843 | MEDIUM | 6.5 | 0.9% | Nov 8, 2021 | IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing mes... |
| CVE-2021-29735 | MEDIUM | 5.4 | 0.5% | Nov 8, 2021 | IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability a... |
| CVE-2021-42770 | MEDIUM | 6.1 | 1.3% | Nov 8, 2021 | A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the... |
| CVE-2021-41733 | MEDIUM | 6.1 | 0.7% | Nov 8, 2021 | Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them. |
| CVE-2021-37850 | MEDIUM | 5.5 | 0.2% | Nov 8, 2021 | ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to ... |
| CVE-2021-32483 | MEDIUM | 5.3 | 0.8% | Nov 8, 2021 | Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard. |
| CVE-2021-22051 | MEDIUM | 6.5 | 0.7% | Nov 8, 2021 | Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request... |
| CVE-2021-32482 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter. |
| CVE-2021-32481 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Cloudera Hue 4.6.0 allows XSS via the type parameter. |
| CVE-2021-29994 | MEDIUM | 6.1 | 0.9% | Nov 8, 2021 | Cloudera Hue 4.6.0 allows XSS. |
| CVE-2021-29243 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS. |
| CVE-2021-42078 | MEDIUM | 6.1 | 0.9% | Nov 8, 2021 | PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/... |
| CVE-2021-31601 | MEDIUM | 6.5 | 1.3% | Nov 8, 2021 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The... |
| CVE-2021-31600 | MEDIUM | 4.3 | 1.0% | Nov 8, 2021 | An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The... |
| CVE-2021-25978 | MEDIUM | 5.4 | 0.5% | Nov 7, 2021 | Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that co... |
| CVE-2021-41251 | MEDIUM | 5.9 | 1.7% | Nov 5, 2021 | @sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform... |
| CVE-2021-41250 | MEDIUM | 4.3 | 0.7% | Nov 5, 2021 | Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted UR... |
| CVE-2021-41227 | MEDIUM | 5.5 | 0.2% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the `ImmutableConst` operation in Tenso... |
| CVE-2021-41222 | MEDIUM | 5.5 | 0.2% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trig... |
| CVE-2021-41213 | MEDIUM | 5.5 | 0.2% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can b... |
| CVE-2021-41218 | MEDIUM | 5.5 | 0.1% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `AllToAll`... |
| CVE-2021-41209 | MEDIUM | 5.5 | 0.1% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution ope... |
| CVE-2021-41207 | MEDIUM | 5.5 | 0.1% | Nov 5, 2021 | TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now