2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29771 | MEDIUM | 5.4 | 0.5% | Nov 2, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-29738 | MEDIUM | 5.4 | 0.5% | Nov 2, 2021 | IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery... |
| CVE-2021-42568 | MEDIUM | 4.3 | 0.5% | Nov 2, 2021 | Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function vi... |
| CVE-2021-27722 | MEDIUM | 5.5 | 1.3% | Nov 2, 2021 | An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data ... |
| CVE-2021-33611 | MEDIUM | 6.1 | 1.0% | Nov 2, 2021 | Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2... |
| CVE-2021-33593 | MEDIUM | 5.3 | 0.7% | Nov 2, 2021 | Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the ad... |
| CVE-2021-25973 | MEDIUM | 6.5 | 0.8% | Nov 2, 2021 | In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even whe... |
| CVE-2021-41310 | MEDIUM | 6.1 | 0.7% | Nov 1, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or ... |
| CVE-2021-43058 | MEDIUM | 6.1 | 0.6% | Nov 1, 2021 | An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exp... |
| CVE-2021-39346 | MEDIUM | 4.8 | 0.9% | Nov 1, 2021 | The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-39340 | MEDIUM | 4.8 | 0.9% | Nov 1, 2021 | The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and ... |
| CVE-2021-38356 | MEDIUM | 6.1 | 0.8% | Nov 1, 2021 | The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2021-31848 | MEDIUM | 6.1 | 0.8% | Nov 1, 2021 | Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a r... |
| CVE-2021-42917 | MEDIUM | 5.5 | 1.9% | Nov 1, 2021 | Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper len... |
| CVE-2021-29213 | MEDIUM | 6.7 | 0.3% | Nov 1, 2021 | A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProL... |
| CVE-2021-27004 | MEDIUM | 5.5 | 0.2% | Nov 1, 2021 | System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which c... |
| CVE-2021-22564 | MEDIUM | 5.5 | 0.3% | Nov 1, 2021 | For certain valid JPEG XL images with a size slightly larger than an integer number of groups (256x256 pixels) when proc... |
| CVE-2021-22563 | MEDIUM | 4.4 | 0.3% | Nov 1, 2021 | Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering sp... |
| CVE-2021-25878 | MEDIUM | 6.1 | 1.1% | Nov 1, 2021 | AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoN... |
| CVE-2021-25876 | MEDIUM | 6.1 | 1.1% | Nov 1, 2021 | AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which... |
| CVE-2021-25875 | MEDIUM | 6.1 | 1.1% | Nov 1, 2021 | AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the... |
| CVE-2021-41973 | MEDIUM | 6.5 | 4.3% | Nov 1, 2021 | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. T... |
| CVE-2021-24813 | MEDIUM | 4.8 | 0.7% | Nov 1, 2021 | The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi... |
| CVE-2021-24808 | MEDIUM | 6.1 | 0.9% | Nov 1, 2021 | The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'sub... |
| CVE-2021-24799 | MEDIUM | 4.3 | 0.5% | Nov 1, 2021 | The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now