2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27703 | MEDIUM | 5.4 | 0.2% | Nov 12, 2024 | Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page. |
| CVE-2021-27702 | HIGH | 7.3 | 0.3% | Nov 12, 2024 | Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the route... |
| CVE-2021-27701 | MEDIUM | 4.7 | 0.2% | Nov 12, 2024 | SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The applic... |
| CVE-2021-27700 | HIGH | 7.6 | 0.3% | Nov 12, 2024 | SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner m... |
| CVE-2021-41737 | HIGH | 7.5 | 0.5% | Nov 10, 2024 | In Faust 2.23.1, an input file with the lines "// r visualisation tCst" and "//process = +: L: abM-^Q;" and "process = r... |
| CVE-2021-35473 | CRITICAL | 9.1 | 0.4% | Nov 10, 2024 | An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e... |
| CVE-2021-4452 | MEDIUM | 5.4 | 0.5% | Oct 16, 2024 | The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet... |
| CVE-2021-4451 | HIGH | 7.2 | 0.6% | Oct 16, 2024 | The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and includ... |
| CVE-2021-4450 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and includi... |
| CVE-2021-4449 | CRITICAL | 9.8 | 5.3% | Oct 16, 2024 | The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '... |
| CVE-2021-4448 | CRITICAL | 9.8 | 1.3% | Oct 16, 2024 | The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including... |
| CVE-2021-4447 | HIGH | 8.8 | 0.4% | Oct 16, 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and inc... |
| CVE-2021-4446 | MEDIUM | 4.3 | 0.3% | Oct 16, 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl... |
| CVE-2021-4445 | MEDIUM | 4.3 | 0.4% | Oct 16, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and i... |
| CVE-2021-4444 | HIGH | 7.3 | 0.3% | Oct 16, 2024 | The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi... |
| CVE-2021-4443 | CRITICAL | 9.8 | 0.7% | Oct 16, 2024 | The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, ... |
| CVE-2021-37577 | MEDIUM | 6.8 | 0.2% | Oct 1, 2024 | Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetoo... |
| CVE-2021-38963 | HIGH | 8 | 0.6% | Sep 25, 2024 | IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the syst... |
| CVE-2021-38023 | HIGH | 8.8 | 0.3% | Sep 23, 2024 | Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit he... |
| CVE-2021-27917 | MEDIUM | 5.4 | 0.3% | Sep 18, 2024 | Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report. |
| CVE-2021-27916 | HIGH | 8.1 | 0.8% | Sep 17, 2024 | Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletio... |
| CVE-2021-27915 | CRITICAL | 9 | 0.6% | Sep 17, 2024 | Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic... |
| CVE-2021-38133 | MEDIUM | 6.5 | 0.3% | Sep 12, 2024 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al... |
| CVE-2021-38132 | CRITICAL | 9.8 | 0.4% | Sep 12, 2024 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al... |
| CVE-2021-38131 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now