2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28601 | MEDIUM | 5.5 | 1.4% | Aug 24, 2021 | Adobe After Effects version 18.2 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a sp... |
| CVE-2021-28600 | MEDIUM | 5.5 | 1.8% | Aug 24, 2021 | Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a special... |
| CVE-2021-39602 | MEDIUM | 6.5 | 0.8% | Aug 23, 2021 | A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a r... |
| CVE-2021-39599 | MEDIUM | 6.1 | 0.6% | Aug 23, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/s... |
| CVE-2021-39609 | MEDIUM | 5.4 | 1.7% | Aug 23, 2021 | Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function. |
| CVE-2021-22253 | MEDIUM | 5.4 | 0.8% | Aug 23, 2021 | Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary ac... |
| CVE-2021-22252 | MEDIUM | 6.5 | 1.1% | Aug 23, 2021 | A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access... |
| CVE-2021-22251 | MEDIUM | 4.3 | 0.8% | Aug 23, 2021 | Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to a... |
| CVE-2021-22249 | MEDIUM | 4.3 | 1.0% | Aug 23, 2021 | A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a use... |
| CVE-2021-22248 | MEDIUM | 5.3 | 1.1% | Aug 23, 2021 | Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized use... |
| CVE-2021-39140 | MEDIUM | 6.3 | 6.0% | Aug 23, 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo... |
| CVE-2021-3731 | MEDIUM | 4.7 | 1.1% | Aug 23, 2021 | LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This... |
| CVE-2021-3730 | MEDIUM | 6.5 | 0.5% | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3729 | MEDIUM | 4.3 | 0.4% | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3728 | MEDIUM | 6.5 | 0.5% | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-33598 | MEDIUM | 6.5 | 0.7% | Aug 23, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component u... |
| CVE-2021-24658 | MEDIUM | 4.8 | 0.7% | Aug 23, 2021 | The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing hi... |
| CVE-2021-24574 | MEDIUM | 4.8 | 0.7% | Aug 23, 2021 | The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privile... |
| CVE-2021-24571 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when g... |
| CVE-2021-24564 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outp... |
| CVE-2021-24561 | MEDIUM | 5.4 | 0.7% | Aug 23, 2021 | The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in t... |
| CVE-2021-24558 | MEDIUM | 5.4 | 0.7% | Aug 23, 2021 | The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise,... |
| CVE-2021-24556 | MEDIUM | 6.1 | 1.3% | Aug 23, 2021 | The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sani... |
| CVE-2021-24549 | MEDIUM | 4.9 | 1.6% | Aug 23, 2021 | The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths... |
| CVE-2021-24547 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now