2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32760 | MEDIUM | 6.3 | 1.6% | Jul 19, 2021 | containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and ext... |
| CVE-2021-34618 | MEDIUM | 6.5 | 0.5% | Jul 19, 2021 | A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in versi... |
| CVE-2021-34617 | MEDIUM | 6.1 | 0.6% | Jul 19, 2021 | A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve... |
| CVE-2021-34821 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP ... |
| CVE-2021-36797 | MEDIUM | 6.8 | 0.3% | Jul 19, 2021 | In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device.... |
| CVE-2021-29780 | MEDIUM | 4.7 | 0.7% | Jul 19, 2021 | IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should no... |
| CVE-2021-20507 | MEDIUM | 5.4 | 0.5% | Jul 19, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-35043 | MEDIUM | 6.1 | 1.5% | Jul 19, 2021 | OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected)... |
| CVE-2021-34817 | MEDIUM | 6.1 | 1.3% | Jul 19, 2021 | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary ... |
| CVE-2021-32014 | MEDIUM | 5.5 | 0.9% | Jul 19, 2021 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xl... |
| CVE-2021-32013 | MEDIUM | 5.5 | 0.9% | Jul 19, 2021 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ... |
| CVE-2021-32012 | MEDIUM | 5.5 | 0.9% | Jul 19, 2021 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ... |
| CVE-2021-3279 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | sz.chat version 4 allows injection of web scripts and HTML in the message box. |
| CVE-2021-35968 | MEDIUM | 4.3 | 1.0% | Jul 19, 2021 | The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly.... |
| CVE-2021-35967 | MEDIUM | 5.3 | 1.3% | Jul 19, 2021 | The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attack... |
| CVE-2021-35966 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing... |
| CVE-2021-24482 | MEDIUM | 4.8 | 0.7% | Jul 19, 2021 | The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high ... |
| CVE-2021-24452 | MEDIUM | 6.1 | 2.0% | Jul 19, 2021 | The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the... |
| CVE-2021-24447 | MEDIUM | 5.3 | 1.4% | Jul 19, 2021 | The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() ... |
| CVE-2021-24436 | MEDIUM | 6.1 | 1.9% | Jul 19, 2021 | The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulne... |
| CVE-2021-36772 | MEDIUM | 6.1 | 0.9% | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. |
| CVE-2021-36771 | MEDIUM | 6.1 | 0.9% | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. |
| CVE-2021-36769 | MEDIUM | 5.3 | 1.0% | Jul 17, 2021 | A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop befo... |
| CVE-2021-3614 | MEDIUM | 6.8 | 0.2% | Jul 16, 2021 | A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevat... |
| CVE-2021-3453 | MEDIUM | 4.6 | 0.2% | Jul 16, 2021 | Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now