2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25090 | MEDIUM | 5.4 | 0.6% | Apr 11, 2022 | The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in vari... |
| CVE-2021-24987 | MEDIUM | 6.1 | 1.9% | Apr 11, 2022 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape t... |
| CVE-2021-24986 | MEDIUM | 6.1 | 0.8% | Apr 11, 2022 | The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attri... |
| CVE-2021-32162 | HIGH | 8.8 | 2.6% | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature. |
| CVE-2021-32161 | MEDIUM | 6.1 | 2.0% | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature. |
| CVE-2021-32160 | MEDIUM | 6.1 | 2.0% | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature. |
| CVE-2021-32159 | HIGH | 8.8 | 2.3% | Apr 11, 2022 | A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature. |
| CVE-2021-32158 | MEDIUM | 6.1 | 2.0% | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature. |
| CVE-2021-32157 | CRITICAL | 9.6 | 4.1% | Apr 11, 2022 | A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. |
| CVE-2021-32156 | HIGH | 8.8 | 2.3% | Apr 11, 2022 | A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature. |
| CVE-2021-43149 | — | — | — | Apr 8, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-43009 | MEDIUM | 6.1 | 2.3% | Apr 8, 2022 | A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the reque... |
| CVE-2021-36293 | MEDIUM | 6.7 | 0.2% | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin... |
| CVE-2021-36290 | MEDIUM | 6.7 | 0.2% | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin... |
| CVE-2021-36288 | CRITICAL | 9.1 | 1.0% | Apr 8, 2022 | Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated... |
| CVE-2021-36287 | CRITICAL | 9.8 | 2.5% | Apr 8, 2022 | Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which ... |
| CVE-2021-43498 | HIGH | 7.5 | 1.6% | Apr 8, 2022 | An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden,... |
| CVE-2021-43503 | — | — | — | Apr 8, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-43517 | CRITICAL | 9.8 | 1.7% | Apr 8, 2022 | FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port whe... |
| CVE-2021-43515 | HIGH | 7.8 | 1.0% | Apr 8, 2022 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the... |
| CVE-2021-43521 | HIGH | 7.5 | 1.3% | Apr 8, 2022 | A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c. |
| CVE-2021-43483 | HIGH | 8 | 0.5% | Apr 8, 2022 | An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a mal... |
| CVE-2021-40656 | HIGH | 8.8 | 1.0% | Apr 8, 2022 | libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867. |
| CVE-2021-41715 | HIGH | 8.8 | 1.0% | Apr 8, 2022 | libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379. |
| CVE-2021-46367 | HIGH | 7.2 | 29.7% | Apr 8, 2022 | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now