2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39333 | HIGH | 8.1 | 1.0% | Nov 1, 2021 | The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce whic... |
| CVE-2021-31849 | HIGH | 7.2 | 1.0% | Nov 1, 2021 | SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacke... |
| CVE-2021-38847 | HIGH | 8.8 | 1.3% | Nov 1, 2021 | S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Adm... |
| CVE-2021-3704 | HIGH | 7.5 | 1.4% | Nov 1, 2021 | Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow a Denial of ... |
| CVE-2021-3440 | HIGH | 7.8 | 0.3% | Nov 1, 2021 | HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevati... |
| CVE-2021-27005 | HIGH | 7.5 | 1.2% | Nov 1, 2021 | Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerabili... |
| CVE-2021-42557 | HIGH | 7.5 | 2.2% | Nov 1, 2021 | In Jeedom through 4.1.19, a bug allows a remote attacker to bypass API access and retrieve users credentials. |
| CVE-2021-25877 | HIGH | 7.2 | 3.1% | Nov 1, 2021 | AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write f... |
| CVE-2021-25874 | HIGH | 7.5 | 1.9% | Nov 1, 2021 | AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter... |
| CVE-2021-27644 | HIGH | 8.8 | 1.9% | Nov 1, 2021 | In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Onl... |
| CVE-2021-24809 | HIGH | 8.8 | 0.7% | Nov 1, 2021 | The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_bett... |
| CVE-2021-24717 | HIGH | 8.8 | 1.3% | Nov 1, 2021 | The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber role... |
| CVE-2021-40348 | HIGH | 8.8 | 1.7% | Nov 1, 2021 | Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize t... |
| CVE-2021-42694 | HIGH | 8.3 | 4.5% | Nov 1, 2021 | An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows... |
| CVE-2021-42574 | HIGH | 8.3 | 12.2% | Nov 1, 2021 | An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual ... |
| CVE-2021-20838 | HIGH | 7.5 | 1.5% | Nov 1, 2021 | Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to... |
| CVE-2021-36808 | HIGH | 7 | 0.2% | Oct 30, 2021 | A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before vers... |
| CVE-2021-1120 | HIGH | 7 | 0.2% | Oct 29, 2021 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the g... |
| CVE-2021-1119 | HIGH | 7.1 | 0.2% | Oct 29, 2021 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a point... |
| CVE-2021-1118 | HIGH | 7.8 | 0.4% | Oct 29, 2021 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to ... |
| CVE-2021-41746 | HIGH | 7.5 | 1.2% | Oct 29, 2021 | SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attac... |
| CVE-2021-41189 | HIGH | 7.2 | 2.0% | Oct 29, 2021 | DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can e... |
| CVE-2021-41645 | HIGH | 8.8 | 3.1% | Oct 29, 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a r... |
| CVE-2021-41675 | HIGH | 7.2 | 3.0% | Oct 29, 2021 | A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.ph... |
| CVE-2021-41186 | HIGH | 7.5 | 2.1% | Oct 29, 2021 | Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The par... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now