2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39133 | MEDIUM | 6.8 | 0.5% | Aug 30, 2021 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1... |
| CVE-2021-34434 | MEDIUM | 5.3 | 1.4% | Aug 30, 2021 | In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make... |
| CVE-2021-38343 | MEDIUM | 6.1 | 0.8% | Aug 30, 2021 | The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB... |
| CVE-2021-37416 | MEDIUM | 6.1 | 2.9% | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. |
| CVE-2021-35061 | MEDIUM | 6.1 | 0.9% | Aug 30, 2021 | Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers... |
| CVE-2021-34668 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in... |
| CVE-2021-22021 | MEDIUM | 5.4 | 0.5% | Aug 30, 2021 | VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user ... |
| CVE-2021-3628 | MEDIUM | 5.4 | 0.9% | Aug 30, 2021 | OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attac... |
| CVE-2021-33003 | MEDIUM | 5.5 | 0.2% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a w... |
| CVE-2021-32991 | MEDIUM | 4.3 | 0.4% | Aug 30, 2021 | Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an att... |
| CVE-2021-27019 | MEDIUM | 4.3 | 0.7% | Aug 30, 2021 | PuppetDB logging included potentially sensitive system information. |
| CVE-2021-22022 | MEDIUM | 4.9 | 1.1% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor ... |
| CVE-2021-29743 | MEDIUM | 5.4 | 0.5% | Aug 30, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows user... |
| CVE-2021-29728 | MEDIUM | 4.9 | 1.0% | Aug 30, 2021 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryp... |
| CVE-2021-27912 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inl... |
| CVE-2021-27911 | MEDIUM | 6.1 | 0.6% | Aug 30, 2021 | Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name an... |
| CVE-2021-27910 | MEDIUM | 6.1 | 0.7% | Aug 30, 2021 | Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management ca... |
| CVE-2021-27909 | MEDIUM | 6.1 | 4.1% | Aug 30, 2021 | For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerab... |
| CVE-2021-24667 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.... |
| CVE-2021-24665 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users wit... |
| CVE-2021-24593 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting ... |
| CVE-2021-24592 | MEDIUM | 4.8 | 0.6% | Aug 30, 2021 | The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron... |
| CVE-2021-24528 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, n... |
| CVE-2021-24438 | MEDIUM | 6.1 | 0.8% | Aug 30, 2021 | The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' p... |
| CVE-2021-24437 | MEDIUM | 6.1 | 0.8% | Aug 30, 2021 | The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter bef... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now