2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44571 | — | — | — | Feb 21, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CV... |
| CVE-2021-44570 | — | — | — | Feb 21, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CV... |
| CVE-2021-44569 | — | — | — | Feb 21, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CV... |
| CVE-2021-44568 | MEDIUM | 6.5 | 1.8% | Feb 21, 2022 | Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via ... |
| CVE-2021-44141 | MEDIUM | 4.3 | 1.1% | Feb 21, 2022 | All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file... |
| CVE-2021-27797 | CRITICAL | 9.8 | 1.3% | Feb 21, 2022 | Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x conta... |
| CVE-2021-27796 | MEDIUM | 6.5 | 0.9% | Feb 21, 2022 | A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated att... |
| CVE-2021-27755 | MEDIUM | 5.5 | 0.2% | Feb 21, 2022 | "Sametime Android potential path traversal vulnerability when using File class" |
| CVE-2021-27753 | MEDIUM | 5.5 | 0.2% | Feb 21, 2022 | "Sametime Android PathTraversal Vulnerability" |
| CVE-2021-26256 | MEDIUM | 6.1 | 0.8% | Feb 21, 2022 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <=... |
| CVE-2021-44142 | HIGH | 8.8 | 74.0% | Feb 21, 2022 | The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SM... |
| CVE-2021-45008 | HIGH | 8.8 | 1.9% | Feb 21, 2022 | Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to adm... |
| CVE-2021-4208 | HIGH | 7.2 | 1.3% | Feb 21, 2022 | The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using ... |
| CVE-2021-25101 | MEDIUM | 4.8 | 0.6% | Feb 21, 2022 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST... |
| CVE-2021-25100 | MEDIUM | 6.1 | 0.9% | Feb 21, 2022 | The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in t... |
| CVE-2021-25099 | MEDIUM | 6.1 | 2.1% | Feb 21, 2022 | The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back i... |
| CVE-2021-25082 | HIGH | 8.8 | 5.4% | Feb 21, 2022 | The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it i... |
| CVE-2021-25075 | LOW | 3.5 | 1.6% | Feb 21, 2022 | The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in ... |
| CVE-2021-25069 | HIGH | 8.8 | 1.5% | Feb 21, 2022 | The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using ... |
| CVE-2021-25060 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its ... |
| CVE-2021-25058 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within ... |
| CVE-2021-25057 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XS... |
| CVE-2021-25055 | MEDIUM | 6.1 | 2.3% | Feb 21, 2022 | The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" ... |
| CVE-2021-24921 | MEDIUM | 6.1 | 0.8% | Feb 21, 2022 | The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before ou... |
| CVE-2021-24867 | CRITICAL | 9.8 | 18.9% | Feb 21, 2022 | Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website bei... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now