2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40994 | MEDIUM | 6.3 | 1.1% | Oct 15, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas... |
| CVE-2021-40721 | MEDIUM | 6.1 | 1.0% | Oct 15, 2021 | Adobe Connect version 11.2.3 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an at... |
| CVE-2021-39864 | MEDIUM | 6.5 | 1.6% | Oct 15, 2021 | Adobe Commerce versions 2.4.2-p2 (and earlier), 2.4.3 (and earlier) and 2.3.7p1 (and earlier) are affected by a cross-si... |
| CVE-2021-40990 | MEDIUM | 6.5 | 1.1% | Oct 15, 2021 | A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ... |
| CVE-2021-3875 | MEDIUM | 5.5 | 1.4% | Oct 15, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3874 | MEDIUM | 6.5 | 1.2% | Oct 15, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2021-39349 | MEDIUM | 4.8 | 1.1% | Oct 15, 2021 | The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation an... |
| CVE-2021-39345 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitizat... |
| CVE-2021-39344 | MEDIUM | 4.8 | 1.0% | Oct 15, 2021 | The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation... |
| CVE-2021-39338 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation... |
| CVE-2021-39337 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa... |
| CVE-2021-39336 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and s... |
| CVE-2021-39335 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validat... |
| CVE-2021-39334 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-39332 | MEDIUM | 4.8 | 0.5% | Oct 15, 2021 | The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-38431 | MEDIUM | 4.3 | 0.7% | Oct 15, 2021 | An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose proj... |
| CVE-2021-42336 | MEDIUM | 4.3 | 0.8% | Oct 15, 2021 | The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remot... |
| CVE-2021-42335 | MEDIUM | 5.4 | 0.6% | Oct 15, 2021 | Easytest bulletin board management function of online learning platform does not filter special characters. After obtain... |
| CVE-2021-42332 | MEDIUM | 4.3 | 0.7% | Oct 15, 2021 | The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s priv... |
| CVE-2021-42331 | MEDIUM | 5.4 | 0.6% | Oct 15, 2021 | The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’... |
| CVE-2021-42329 | MEDIUM | 5.4 | 0.6% | Oct 15, 2021 | The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title p... |
| CVE-2021-36387 | MEDIUM | 5.4 | 1.4% | Oct 14, 2021 | In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploita... |
| CVE-2021-32571 | MEDIUM | 4.9 | 0.8% | Oct 14, 2021 | In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and p... |
| CVE-2021-42227 | MEDIUM | 6.1 | 0.9% | Oct 14, 2021 | Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.htm... |
| CVE-2021-32569 | MEDIUM | 6.1 | 0.6% | Oct 14, 2021 | In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now