2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41747 | MEDIUM | 6.1 | 0.6% | Oct 22, 2021 | Cross-Site Scripting (XSS) vulnerability exists in Csdn APP 4.10.0, which can be exploited by attackers to obtain sensit... |
| CVE-2021-38465 | MEDIUM | 6.5 | 0.8% | Oct 22, 2021 | The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consum... |
| CVE-2021-38455 | MEDIUM | 6.5 | 0.7% | Oct 22, 2021 | The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will... |
| CVE-2021-38451 | MEDIUM | 5.7 | 0.6% | Oct 22, 2021 | The affected product’s proprietary protocol CSC allows for calling numerous function codes. In order to call those funct... |
| CVE-2021-35230 | MEDIUM | 6.7 | 0.3% | Oct 22, 2021 | As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker... |
| CVE-2021-31682 | MEDIUM | 6.1 | 10.5% | Oct 22, 2021 | The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re... |
| CVE-2021-31835 | MEDIUM | 4.8 | 0.5% | Oct 22, 2021 | Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrator... |
| CVE-2021-31834 | MEDIUM | 5.4 | 0.4% | Oct 22, 2021 | Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO admini... |
| CVE-2021-41169 | MEDIUM | 4.8 | 0.6% | Oct 21, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subje... |
| CVE-2021-36869 | MEDIUM | 6.1 | 0.7% | Oct 21, 2021 | Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable para... |
| CVE-2021-27746 | MEDIUM | 5.4 | 0.5% | Oct 21, 2021 | "HCL Connections Security Update for Reflected Cross-Site Scripting (XSS) Vulnerability" |
| CVE-2021-41168 | MEDIUM | 6.5 | 0.9% | Oct 21, 2021 | Snudown is a reddit-specific fork of the Sundown Markdown parser used by GitHub, with Python integration added. In affec... |
| CVE-2021-39357 | MEDIUM | 4.8 | 0.9% | Oct 21, 2021 | The Leaky Paywall WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and... |
| CVE-2021-39356 | MEDIUM | 4.8 | 1.0% | Oct 21, 2021 | The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation a... |
| CVE-2021-39354 | MEDIUM | 4.8 | 0.9% | Oct 21, 2021 | The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end... |
| CVE-2021-39348 | MEDIUM | 4.8 | 5.0% | Oct 21, 2021 | The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom... |
| CVE-2021-39328 | MEDIUM | 4.8 | 0.9% | Oct 21, 2021 | The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $... |
| CVE-2021-42715 | MEDIUM | 5.5 | 1.2% | Oct 21, 2021 | An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines ... |
| CVE-2021-35228 | MEDIUM | 4.7 | 0.6% | Oct 21, 2021 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from header... |
| CVE-2021-35225 | MEDIUM | 6.4 | 0.8% | Oct 21, 2021 | Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath S... |
| CVE-2021-42327 | MEDIUM | 6.7 | 0.8% | Oct 21, 2021 | dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 ... |
| CVE-2021-29883 | MEDIUM | 4.3 | 0.5% | Oct 21, 2021 | IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on... |
| CVE-2021-28496 | MEDIUM | 6.5 | 0.4% | Oct 21, 2021 | On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the pass... |
| CVE-2021-28975 | MEDIUM | 6.1 | 0.9% | Oct 21, 2021 | WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted serve... |
| CVE-2021-35512 | MEDIUM | 6.5 | 1.6% | Oct 21, 2021 | An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now