2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30845 | MEDIUM | 5.5 | 0.2% | Oct 19, 2021 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6. A local us... |
| CVE-2021-30828 | MEDIUM | 5.5 | 0.3% | Oct 19, 2021 | This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 1... |
| CVE-2021-30819 | MEDIUM | 5.5 | 0.8% | Oct 19, 2021 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Process... |
| CVE-2021-30811 | MEDIUM | 5.5 | 0.3% | Oct 19, 2021 | This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker ... |
| CVE-2021-30810 | MEDIUM | 4.3 | 0.5% | Oct 19, 2021 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchO... |
| CVE-2021-3879 | MEDIUM | 5.4 | 0.8% | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3863 | MEDIUM | 6.1 | 0.8% | Oct 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3851 | MEDIUM | 5.4 | 0.6% | Oct 19, 2021 | firefly-iii is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-38482 | MEDIUM | 4.8 | 0.5% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to ... |
| CVE-2021-38476 | MEDIUM | 5.3 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and valida... |
| CVE-2021-38472 | MEDIUM | 4.7 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTION... |
| CVE-2021-38468 | MEDIUM | 4.8 | 0.5% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may ... |
| CVE-2021-38466 | MEDIUM | 6.1 | 0.7% | Oct 19, 2021 | InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client... |
| CVE-2021-25968 | MEDIUM | 5.4 | 0.5% | Oct 19, 2021 | In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged applicatio... |
| CVE-2021-20836 | MEDIUM | 6.5 | 0.8% | Oct 19, 2021 | Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privile... |
| CVE-2021-42650 | MEDIUM | 6.1 | 0.6% | Oct 18, 2021 | Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates. |
| CVE-2021-41156 | MEDIUM | 5.4 | 0.5% | Oct 18, 2021 | anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden c... |
| CVE-2021-41151 | MEDIUM | 4.9 | 1.3% | Oct 18, 2021 | Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitiv... |
| CVE-2021-42055 | MEDIUM | 6.8 | 0.2% | Oct 18, 2021 | ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically... |
| CVE-2021-29878 | MEDIUM | 5.4 | 0.5% | Oct 18, 2021 | IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2021-32609 | MEDIUM | 5.4 | 1.6% | Oct 18, 2021 | Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker ... |
| CVE-2021-24760 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow u... |
| CVE-2021-24752 | MEDIUM | 5.7 | 0.4% | Oct 18, 2021 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, wh... |
| CVE-2021-24743 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding post... |
| CVE-2021-24740 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, w... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now