2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39144 | HIGH | 8.5 | 98.5% | Aug 23, 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo... |
| CVE-2021-39141 | HIGH | 8.5 | 16.2% | Aug 23, 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo... |
| CVE-2021-39139 | HIGH | 8.8 | 4.6% | Aug 23, 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo... |
| CVE-2021-29802 | HIGH | 7.5 | 0.6% | Aug 23, 2021 | IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creat... |
| CVE-2021-29704 | HIGH | 7.5 | 0.7% | Aug 23, 2021 | IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens... |
| CVE-2021-24602 | HIGH | 8.8 | 1.5% | Aug 23, 2021 | The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set... |
| CVE-2021-24565 | HIGH | 8.8 | 0.7% | Aug 23, 2021 | The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings,... |
| CVE-2021-24562 | HIGH | 7.5 | 1.6% | Aug 23, 2021 | The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 ... |
| CVE-2021-24557 | HIGH | 7.2 | 1.5% | Aug 23, 2021 | The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped b... |
| CVE-2021-24555 | HIGH | 8.8 | 0.8% | Aug 23, 2021 | The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter wh... |
| CVE-2021-24554 | HIGH | 7.2 | 5.7% | Aug 23, 2021 | The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter be... |
| CVE-2021-24553 | HIGH | 7.2 | 1.6% | Aug 23, 2021 | The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before u... |
| CVE-2021-24552 | HIGH | 7.2 | 1.6% | Aug 23, 2021 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parame... |
| CVE-2021-24550 | HIGH | 7.2 | 1.6% | Aug 23, 2021 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter befor... |
| CVE-2021-24506 | HIGH | 8.8 | 1.4% | Aug 23, 2021 | The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape... |
| CVE-2021-24497 | HIGH | 7.2 | 1.3% | Aug 23, 2021 | The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user ... |
| CVE-2021-35940 | HIGH | 7.1 | 1.2% | Aug 23, 2021 | An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE... |
| CVE-2021-39291 | HIGH | 8.8 | 1.5% | Aug 23, 2021 | Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, ... |
| CVE-2021-39289 | HIGH | 7.5 | 1.0% | Aug 23, 2021 | Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmwa... |
| CVE-2021-39245 | HIGH | 7.5 | 1.3% | Aug 23, 2021 | Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affec... |
| CVE-2021-39244 | HIGH | 8.8 | 3.5% | Aug 23, 2021 | Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xto... |
| CVE-2021-39371 | HIGH | 7.5 | 1.5% | Aug 23, 2021 | An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server ... |
| CVE-2021-36015 | HIGH | 7.8 | 2.6% | Aug 20, 2021 | Adobe Media Encoder version 15.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially... |
| CVE-2021-36011 | HIGH | 7.8 | 1.9% | Aug 20, 2021 | Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained w... |
| CVE-2021-36009 | HIGH | 7.8 | 3.0% | Aug 20, 2021 | Adobe Illustrator version 25.2.3 (and earlier) is affected by an memory corruption vulnerability when parsing a speciall... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now