2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25019 | MEDIUM | 6.1 | 0.8% | Mar 21, 2022 | The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it b... |
| CVE-2021-24905 | HIGH | 8 | 0.7% | Mar 21, 2022 | The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_... |
| CVE-2021-45117 | MEDIUM | 6.5 | 1.4% | Mar 21, 2022 | The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointe... |
| CVE-2021-45878 | CRITICAL | 9.1 | 1.1% | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the we... |
| CVE-2021-45877 | CRITICAL | 9.8 | 1.1% | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /e... |
| CVE-2021-45876 | CRITICAL | 9.8 | 1.5% | Mar 21, 2022 | Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of th... |
| CVE-2021-36100 | HIGH | 8.8 | 1.3% | Mar 21, 2022 | Specially crafted string in OTRS system configuration can allow the execution of any system command. |
| CVE-2021-42194 | HIGH | 7.2 | 1.1% | Mar 20, 2022 | The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the... |
| CVE-2021-39384 | CRITICAL | 9.8 | 1.2% | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.j... |
| CVE-2021-39383 | CRITICAL | 9.8 | 2.9% | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysP... |
| CVE-2021-44345 | HIGH | 7.5 | 1.1% | Mar 20, 2022 | Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Inject... |
| CVE-2021-4031 | HIGH | 7.5 | 0.5% | Mar 18, 2022 | Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associate... |
| CVE-2021-44760 | MEDIUM | 5.4 | 0.5% | Mar 18, 2022 | Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 vers... |
| CVE-2021-30771 | HIGH | 7.8 | 1.3% | Mar 18, 2022 | An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, iOS 14.6... |
| CVE-2021-27789 | MEDIUM | 6.5 | 0.8% | Mar 18, 2022 | The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements... |
| CVE-2021-23209 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP ... |
| CVE-2021-23150 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pag... |
| CVE-2021-39046 | MEDIUM | 4.9 | 0.9% | Mar 18, 2022 | IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user cre... |
| CVE-2021-29899 | MEDIUM | 6.5 | 1.0% | Mar 18, 2022 | IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of ser... |
| CVE-2021-45835 | CRITICAL | 9.8 | 3.0% | Mar 18, 2022 | The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the... |
| CVE-2021-45834 | CRITICAL | 9.8 | 2.3% | Mar 18, 2022 | An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass... |
| CVE-2021-22571 | MEDIUM | 5.5 | 0.2% | Mar 18, 2022 | A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process ... |
| CVE-2021-45868 | MEDIUM | 5.5 | 1.3% | Mar 18, 2022 | In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk).... |
| CVE-2021-45968 | HIGH | 7.5 | 10.7% | Mar 18, 2022 | An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho... |
| CVE-2021-45967 | CRITICAL | 9.8 | 20.8% | Mar 18, 2022 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now