2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21750 | HIGH | 7.8 | 0.3% | Dec 27, 2021 | ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task mod... |
| CVE-2021-43856 | MEDIUM | 5.4 | 0.9% | Dec 27, 2021 | Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through... |
| CVE-2021-43855 | MEDIUM | 5.4 | 0.9% | Dec 27, 2021 | Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through... |
| CVE-2021-43845 | CRITICAL | 9.1 | 3.7% | Dec 27, 2021 | PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR messa... |
| CVE-2021-38961 | MEDIUM | 6.1 | 0.6% | Dec 27, 2021 | IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c... |
| CVE-2021-45232 | CRITICAL | 9.8 | 85.9% | Dec 27, 2021 | In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the ... |
| CVE-2021-45339 | HIGH | 7.8 | 0.3% | Dec 27, 2021 | Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "... |
| CVE-2021-45338 | HIGH | 7.8 | 0.4% | Dec 27, 2021 | Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privi... |
| CVE-2021-45337 | HIGH | 8.8 | 0.4% | Dec 27, 2021 | Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with ... |
| CVE-2021-45336 | HIGH | 8.8 | 0.5% | Dec 27, 2021 | Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed co... |
| CVE-2021-45335 | HIGH | 8.8 | 0.4% | Dec 27, 2021 | Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to con... |
| CVE-2021-4173 | HIGH | 7.8 | 1.6% | Dec 27, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-24998 | HIGH | 7.5 | 1.2% | Dec 27, 2021 | The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly gen... |
| CVE-2021-24997 | MEDIUM | 6.5 | 2.8% | Dec 27, 2021 | The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any... |
| CVE-2021-24992 | MEDIUM | 4.8 | 0.6% | Dec 27, 2021 | The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before out... |
| CVE-2021-24988 | MEDIUM | 5.4 | 0.3% | Dec 27, 2021 | The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the Syste... |
| CVE-2021-24984 | MEDIUM | 6.1 | 0.8% | Dec 27, 2021 | The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved paramete... |
| CVE-2021-24980 | MEDIUM | 6.1 | 0.8% | Dec 27, 2021 | The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter befor... |
| CVE-2021-24979 | MEDIUM | 6.1 | 1.9% | Dec 27, 2021 | The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an a... |
| CVE-2021-24969 | MEDIUM | 5.4 | 0.6% | Dec 27, 2021 | The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputti... |
| CVE-2021-24967 | MEDIUM | 6.1 | 1.2% | Dec 27, 2021 | The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead valu... |
| CVE-2021-24902 | MEDIUM | 4.8 | 0.6% | Dec 27, 2021 | The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publis... |
| CVE-2021-24797 | MEDIUM | 6.1 | 1.2% | Dec 27, 2021 | The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events befor... |
| CVE-2021-24753 | HIGH | 7.2 | 1.5% | Dec 27, 2021 | The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the p... |
| CVE-2021-45711 | HIGH | 7.5 | 1.3% | Dec 27, 2021 | An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now