2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37209 | MEDIUM | 6.7 | 0.4% | Mar 8, 2022 | A vulnerability has been identified in RUGGEDCOM i800 (All versions < V4.3.8), RUGGEDCOM i801 (All versions < V4.3.8), R... |
| CVE-2021-37208 | CRITICAL | 9.6 | 0.5% | Mar 8, 2022 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80... |
| CVE-2021-43944 | HIGH | 7.2 | 2.2% | Mar 8, 2022 | This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has ... |
| CVE-2021-36809 | MEDIUM | 6 | 0.2% | Mar 8, 2022 | A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potent... |
| CVE-2021-38989 | MEDIUM | 5.5 | 0.2% | Mar 7, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel... |
| CVE-2021-38988 | MEDIUM | 5.5 | 0.2% | Mar 7, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel... |
| CVE-2021-4199 | HIGH | 7.8 | 0.8% | Mar 7, 2022 | Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used... |
| CVE-2021-4198 | MEDIUM | 6.1 | 0.6% | Mar 7, 2022 | A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Inter... |
| CVE-2021-25098 | MEDIUM | 6.5 | 0.5% | Mar 7, 2022 | The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, al... |
| CVE-2021-25087 | HIGH | 7.5 | 1.5% | Mar 7, 2022 | The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo... |
| CVE-2021-25039 | MEDIUM | 6.1 | 0.8% | Mar 7, 2022 | The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_conte... |
| CVE-2021-25038 | MEDIUM | 6.1 | 0.8% | Mar 7, 2022 | The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog... |
| CVE-2021-25009 | MEDIUM | 5.3 | 1.2% | Mar 7, 2022 | The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensiti... |
| CVE-2021-24961 | MEDIUM | 5.4 | 0.8% | Mar 7, 2022 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does ... |
| CVE-2021-24960 | MEDIUM | 5.4 | 0.8% | Mar 7, 2022 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allow... |
| CVE-2021-24953 | MEDIUM | 6.1 | 0.8% | Mar 7, 2022 | The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputti... |
| CVE-2021-24952 | HIGH | 8.8 | 1.3% | Mar 7, 2022 | The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet... |
| CVE-2021-24826 | MEDIUM | 5.4 | 0.6% | Mar 7, 2022 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which c... |
| CVE-2021-24825 | MEDIUM | 4.3 | 0.4% | Mar 7, 2022 | The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, whic... |
| CVE-2021-24824 | MEDIUM | 4.3 | 0.8% | Mar 7, 2022 | The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated use... |
| CVE-2021-24821 | MEDIUM | 5.4 | 0.6% | Mar 7, 2022 | The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-S... |
| CVE-2021-24810 | MEDIUM | 4.8 | 0.6% | Mar 7, 2022 | The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting th... |
| CVE-2021-24778 | HIGH | 7.2 | 1.3% | Mar 7, 2022 | The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or ... |
| CVE-2021-24777 | HIGH | 7.2 | 1.3% | Mar 7, 2022 | The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the s... |
| CVE-2021-24216 | HIGH | 7.2 | 1.7% | Mar 7, 2022 | The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows admin... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now