2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24762 | CRITICAL | 9.8 | 86.9% | Feb 1, 2022 | The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using... |
| CVE-2021-24761 | MEDIUM | 6.5 | 0.6% | Feb 1, 2022 | The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not ha... |
| CVE-2021-24707 | MEDIUM | 4.8 | 0.6% | Feb 1, 2022 | The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi... |
| CVE-2021-24686 | MEDIUM | 4.8 | 0.7% | Feb 1, 2022 | The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in... |
| CVE-2021-24648 | MEDIUM | 6.1 | 0.9% | Feb 1, 2022 | The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before ... |
| CVE-2021-43859 | HIGH | 7.5 | 8.2% | Feb 1, 2022 | XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a ... |
| CVE-2021-41040 | HIGH | 7.5 | 1.4% | Feb 1, 2022 | In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-... |
| CVE-2021-3534 | — | — | — | Feb 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-34981. Reason: This candidate is a reservation d... |
| CVE-2021-46669 | HIGH | 7.5 | 2.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is us... |
| CVE-2021-46668 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact ... |
| CVE-2021-46667 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. |
| CVE-2021-46666 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE c... |
| CVE-2021-46665 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations. |
| CVE-2021-46664 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr. |
| CVE-2021-46663 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. |
| CVE-2021-46662 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with... |
| CVE-2021-46661 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common t... |
| CVE-2021-46459 | HIGH | 7.5 | 1.4% | Jan 31, 2022 | Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source... |
| CVE-2021-44114 | MEDIUM | 4.8 | 1.0% | Jan 31, 2022 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows r... |
| CVE-2021-42635 | HIGH | 8.1 | 5.7% | Jan 31, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code e... |
| CVE-2021-42631 | HIGH | 8.1 | 6.3% | Jan 31, 2022 | PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code... |
| CVE-2021-46458 | HIGH | 7.5 | 1.4% | Jan 31, 2022 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post... |
| CVE-2021-40042 | MEDIUM | 6.5 | 0.6% | Jan 31, 2022 | There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process an... |
| CVE-2021-40033 | MEDIUM | 5.5 | 0.2% | Jan 31, 2022 | There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software... |
| CVE-2021-31617 | CRITICAL | 9.8 | 2.1% | Jan 31, 2022 | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 thro... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now