2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43098 | HIGH | 7.2 | 1.2% | Mar 28, 2022 | A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. |
| CVE-2021-43097 | HIGH | 7.2 | 2.2% | Mar 28, 2022 | A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a ma... |
| CVE-2021-4191 | MEDIUM | 5.3 | 80.0% | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv... |
| CVE-2021-39876 | MEDIUM | 4.3 | 0.8% | Mar 28, 2022 | In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of p... |
| CVE-2021-25071 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in a... |
| CVE-2021-25070 | CRITICAL | 9.8 | 1.6% | Mar 28, 2022 | The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in ... |
| CVE-2021-25068 | HIGH | 7.2 | 1.3% | Mar 28, 2022 | The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter wh... |
| CVE-2021-25064 | HIGH | 7.2 | 1.3% | Mar 28, 2022 | The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a... |
| CVE-2021-25012 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them... |
| CVE-2021-24978 | MEDIUM | 5.3 | 0.5% | Mar 28, 2022 | The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and... |
| CVE-2021-24962 | HIGH | 8.8 | 2.8% | Mar 28, 2022 | The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to ... |
| CVE-2021-24746 | MEDIUM | 6.1 | 2.2% | Mar 28, 2022 | The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back i... |
| CVE-2021-44124 | HIGH | 7.5 | 1.9% | Mar 28, 2022 | Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input d... |
| CVE-2021-44103 | — | — | — | Mar 28, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42192. Reason: This candidate is a duplicate of ... |
| CVE-2021-43721 | MEDIUM | 6.1 | 1.0% | Mar 28, 2022 | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution... |
| CVE-2021-43725 | MEDIUM | 6.1 | 2.6% | Mar 28, 2022 | There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remot... |
| CVE-2021-46434 | MEDIUM | 5.3 | 0.9% | Mar 28, 2022 | EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the appl... |
| CVE-2021-46433 | CRITICAL | 10 | 1.1% | Mar 28, 2022 | In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox t... |
| CVE-2021-45491 | MEDIUM | 6.5 | 0.8% | Mar 28, 2022 | 3CX System through 2022-03-17 stores cleartext passwords in a database. |
| CVE-2021-45490 | CRITICAL | 9.1 | 1.1% | Mar 28, 2022 | The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 l... |
| CVE-2021-44617 | CRITICAL | 9.8 | 2.1% | Mar 28, 2022 | A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.... |
| CVE-2021-44213 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. |
| CVE-2021-44212 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring. |
| CVE-2021-44211 | MEDIUM | 5.4 | 0.7% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature. |
| CVE-2021-44210 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now