2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24428 | MEDIUM | 4.8 | 0.5% | Aug 2, 2021 | The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving an... |
| CVE-2021-24425 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin be... |
| CVE-2021-3351 | MEDIUM | 5.4 | 0.5% | Aug 2, 2021 | OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page. |
| CVE-2021-34556 | MEDIUM | 5.5 | 0.4% | Aug 2, 2021 | In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via ... |
| CVE-2021-35477 | MEDIUM | 5.5 | 0.5% | Aug 2, 2021 | In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via ... |
| CVE-2021-33617 | MEDIUM | 5.3 | 2.1% | Jul 31, 2021 | Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&use... |
| CVE-2021-34630 | MEDIUM | 6.1 | 1.6% | Jul 30, 2021 | In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of al... |
| CVE-2021-34629 | MEDIUM | 4.3 | 0.7% | Jul 30, 2021 | The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/... |
| CVE-2021-22521 | MEDIUM | 6.7 | 0.2% | Jul 30, 2021 | A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting ve... |
| CVE-2021-3636 | MEDIUM | 4.6 | 0.3% | Jul 30, 2021 | It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly... |
| CVE-2021-29298 | MEDIUM | 5.3 | 0.8% | Jul 30, 2021 | Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of ... |
| CVE-2021-29297 | MEDIUM | 5.3 | 0.8% | Jul 30, 2021 | Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service an... |
| CVE-2021-37746 | MEDIUM | 6.1 | 1.3% | Jul 30, 2021 | textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have suffici... |
| CVE-2021-37743 | MEDIUM | 5.4 | 0.7% | Jul 30, 2021 | app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON fo... |
| CVE-2021-37742 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster re... |
| CVE-2021-37606 | MEDIUM | 5.3 | 0.7% | Jul 30, 2021 | Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision ... |
| CVE-2021-37600 | MEDIUM | 5.5 | 0.7% | Jul 30, 2021 | An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use... |
| CVE-2021-37596 | MEDIUM | 6.1 | 0.6% | Jul 30, 2021 | Telegram Web K Alpha 0.6.1 allows XSS via a document name. |
| CVE-2021-37588 | MEDIUM | 5.9 | 0.9% | Jul 30, 2021 | In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data. |
| CVE-2021-37587 | MEDIUM | 6.5 | 0.8% | Jul 30, 2021 | In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data. |
| CVE-2021-36605 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user lis... |
| CVE-2021-35479 | MEDIUM | 5.4 | 13.2% | Jul 30, 2021 | Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log functio... |
| CVE-2021-35478 | MEDIUM | 5.4 | 76.6% | Jul 30, 2021 | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. ... |
| CVE-2021-31878 | MEDIUM | 6.5 | 2.4% | Jul 30, 2021 | An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must ... |
| CVE-2021-30483 | MEDIUM | 5.3 | 2.2% | Jul 30, 2021 | isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now