2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36826 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerabi... |
| CVE-2021-33010 | HIGH | 7.5 | 1.0% | Apr 4, 2022 | An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught,... |
| CVE-2021-33008 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requi... |
| CVE-2021-32994 | HIGH | 7.5 | 1.6% | Apr 4, 2022 | Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly v... |
| CVE-2021-32986 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user... |
| CVE-2021-32985 | HIGH | 7.2 | 0.5% | Apr 4, 2022 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communicatio... |
| CVE-2021-32984 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the... |
| CVE-2021-32982 | HIGH | 7.5 | 0.6% | Apr 4, 2022 | Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during ... |
| CVE-2021-32981 | HIGH | 7.2 | 1.2% | Apr 4, 2022 | AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to ... |
| CVE-2021-32980 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional sof... |
| CVE-2021-32978 | HIGH | 7.5 | 1.0% | Apr 4, 2022 | The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previ... |
| CVE-2021-32977 | HIGH | 7.2 | 0.6% | Apr 4, 2022 | AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic sign... |
| CVE-2021-43464 | HIGH | 8.8 | 1.4% | Apr 4, 2022 | A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when th... |
| CVE-2021-43463 | HIGH | 7.8 | 0.4% | Apr 4, 2022 | An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service execu... |
| CVE-2021-43462 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter. |
| CVE-2021-43461 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter. |
| CVE-2021-43460 | HIGH | 7.8 | 0.4% | Apr 4, 2022 | An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExp... |
| CVE-2021-43459 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parame... |
| CVE-2021-25113 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its sett... |
| CVE-2021-25048 | MEDIUM | 5.4 | 0.6% | Apr 4, 2022 | The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creatin... |
| CVE-2021-43458 | HIGH | 7.8 | 0.4% | Apr 4, 2022 | An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) V... |
| CVE-2021-43457 | HIGH | 7.8 | 0.3% | Apr 4, 2022 | An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service pat... |
| CVE-2021-43456 | HIGH | 7.8 | 0.4% | Apr 4, 2022 | An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the R... |
| CVE-2021-43455 | HIGH | 7.8 | 0.4% | Apr 4, 2022 | An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path. |
| CVE-2021-43454 | HIGH | 7.8 | 0.4% | Apr 4, 2022 | An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now