2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33730 | HIGH | 7.2 | 27.7% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). A privileged authenticated attacker... |
| CVE-2021-33729 | HIGH | 8.8 | 2.3% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). An authenticated attacker that is a... |
| CVE-2021-33728 | HIGH | 7.2 | 1.5% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to uploa... |
| CVE-2021-33726 | HIGH | 7.5 | 1.2% | Oct 12, 2021 | A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to downl... |
| CVE-2021-27395 | HIGH | 8.1 | 0.8% | Oct 12, 2021 | A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Histor... |
| CVE-2021-42260 | HIGH | 7.5 | 3.1% | Oct 11, 2021 | TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case... |
| CVE-2021-42257 | HIGH | 7.1 | 0.4% | Oct 11, 2021 | check_smart before 6.9.1 allows unintended drive access by an unprivileged user because it only checks for a substring m... |
| CVE-2021-42252 | HIGH | 7.8 | 0.4% | Oct 11, 2021 | An issue was discovered in aspeed_lpc_ctrl_mmap in drivers/soc/aspeed/aspeed-lpc-ctrl.c in the Linux kernel before 5.14.... |
| CVE-2021-40189 | HIGH | 7.2 | 1.7% | Oct 11, 2021 | PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webr... |
| CVE-2021-40188 | HIGH | 7.2 | 1.3% | Oct 11, 2021 | PHPFusion 9.03.110 is affected by an arbitrary file upload vulnerability. The File Manager function in admin panel does ... |
| CVE-2021-27002 | HIGH | 7.5 | 1.3% | Oct 11, 2021 | NetApp Cloud Manager versions prior to 3.9.10 are susceptible to a vulnerability which could allow a remote unauthentica... |
| CVE-2021-25633 | HIGH | 7.5 | 0.7% | Oct 11, 2021 | LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt... |
| CVE-2021-20122 | HIGH | 7.2 | 6.5% | Oct 11, 2021 | The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vu... |
| CVE-2021-39317 | HIGH | 8.8 | 1.7% | Oct 11, 2021 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads... |
| CVE-2021-27665 | HIGH | 7.5 | 1.5% | Oct 11, 2021 | An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a spe... |
| CVE-2021-0583 | HIGH | 7.3 | 0.1% | Oct 11, 2021 | In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjack... |
| CVE-2021-29005 | HIGH | 8.8 | 1.8% | Oct 11, 2021 | Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute ch... |
| CVE-2021-29004 | HIGH | 8.8 | 2.1% | Oct 11, 2021 | rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-... |
| CVE-2021-40884 | HIGH | 8.1 | 0.9% | Oct 11, 2021 | Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids ... |
| CVE-2021-24711 | HIGH | 8.8 | 0.7% | Oct 11, 2021 | The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CS... |
| CVE-2021-24651 | HIGH | 7.5 | 1.6% | Oct 11, 2021 | The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_po... |
| CVE-2021-24546 | HIGH | 8.8 | 1.8% | Oct 11, 2021 | The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Condit... |
| CVE-2021-41832 | HIGH | 7.5 | 1.3% | Oct 11, 2021 | It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apach... |
| CVE-2021-41830 | HIGH | 7.5 | 1.3% | Oct 11, 2021 | It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All ve... |
| CVE-2021-41801 | HIGH | 8.8 | 1.1% | Oct 11, 2021 | The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now