2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37114 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | There is an Out-of-bounds read vulnerability in Smartphone.Successful exploitation of this vulnerability may affect serv... |
| CVE-2021-37113 | HIGH | 7.5 | 0.7% | Jan 3, 2022 | There is a Privilege escalation vulnerability with the file system component in Smartphone.Successful exploitation of th... |
| CVE-2021-37112 | MEDIUM | 5.3 | 0.5% | Jan 3, 2022 | Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this v... |
| CVE-2021-37111 | HIGH | 7.5 | 0.7% | Jan 3, 2022 | There is a Memory leakage vulnerability in Smartphone.Successful exploitation of this vulnerability may cause memory exh... |
| CVE-2021-37110 | HIGH | 7.5 | 0.7% | Jan 3, 2022 | There is a Timing design defects in Smartphone.Successful exploitation of this vulnerability may affect service confiden... |
| CVE-2021-37098 | HIGH | 7.5 | 0.7% | Jan 3, 2022 | Hilinksvc service exists a Data Processing Errors vulnerability .Successful exploitation of this vulnerability may cause... |
| CVE-2021-20148 | MEDIUM | 4.3 | 1.1% | Jan 3, 2022 | ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web roo... |
| CVE-2021-20147 | MEDIUM | 5.3 | 6.9% | Jan 3, 2022 | ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of th... |
| CVE-2021-45817 | — | — | — | Jan 3, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11689. Reason: This candidate is a duplicate of ... |
| CVE-2021-46109 | MEDIUM | 6.1 | 0.7% | Jan 3, 2022 | Invalid input sanitizing leads to reflected Cross Site Scripting (XSS) in ASUS RT-AC52U_B1 3.0.0.4.380.10931 can lead to... |
| CVE-2021-3837 | MEDIUM | 6.1 | 0.5% | Jan 3, 2022 | openwhyd is vulnerable to Improper Authorization |
| CVE-2021-45428 | CRITICAL | 9.8 | 56.9% | Jan 3, 2022 | TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can uploa... |
| CVE-2021-44674 | MEDIUM | 6.5 | 1.3% | Jan 3, 2022 | An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticate... |
| CVE-2021-25040 | MEDIUM | 6.1 | 0.8% | Jan 3, 2022 | The Booking Calendar WordPress plugin before 8.9.2 does not sanitise and escape the booking_type parameter before output... |
| CVE-2021-25030 | HIGH | 8.8 | 1.6% | Jan 3, 2022 | The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using ... |
| CVE-2021-25027 | MEDIUM | 6.1 | 0.9% | Jan 3, 2022 | The PowerPack Addons for Elementor WordPress plugin before 2.6.2 does not escape the tab parameter before outputting it ... |
| CVE-2021-25023 | HIGH | 7.2 | 1.1% | Jan 3, 2022 | The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_ta... |
| CVE-2021-25022 | MEDIUM | 6.1 | 1.1% | Jan 3, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.66 does not sanitise and escape the backup_timestam... |
| CVE-2021-25021 | MEDIUM | 4.9 | 1.0% | Jan 3, 2022 | The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allow... |
| CVE-2021-25020 | MEDIUM | 4.9 | 1.0% | Jan 3, 2022 | The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, al... |
| CVE-2021-25016 | MEDIUM | 6.1 | 1.8% | Jan 3, 2022 | The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the searc... |
| CVE-2021-25001 | MEDIUM | 6.1 | 0.8% | Jan 3, 2022 | The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_create_products_xml_resul... |
| CVE-2021-25000 | MEDIUM | 6.1 | 0.8% | Jan 3, 2022 | The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_delete_role parameter bef... |
| CVE-2021-24999 | MEDIUM | 6.1 | 0.8% | Jan 3, 2022 | The Booster for WooCommerce WordPress plugin before 5.4.9 does not sanitise and escape the wcj_notice parameter before o... |
| CVE-2021-24991 | MEDIUM | 4.8 | 1.2% | Jan 3, 2022 | The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section paramete... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now