2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28815 | MEDIUM | 4.9 | 1.7% | Jun 16, 2021 | Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, t... |
| CVE-2021-3535 | MEDIUM | 6.1 | 0.6% | Jun 16, 2021 | Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Fil... |
| CVE-2021-32676 | MEDIUM | 6.5 | 1.0% | Jun 16, 2021 | Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Tal... |
| CVE-2021-32623 | MEDIUM | 6.5 | 1.3% | Jun 16, 2021 | Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to ... |
| CVE-2021-28858 | MEDIUM | 5.5 | 0.3% | Jun 15, 2021 | TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monit... |
| CVE-2021-33887 | MEDIUM | 6.8 | 0.3% | Jun 15, 2021 | Insufficient verification of data authenticity in Peloton TTR01 up to and including PTV55G allows an attacker with physi... |
| CVE-2021-32683 | MEDIUM | 6.1 | 0.8% | Jun 15, 2021 | wire-webapp is the web version of Wire, an open-source messenger. A cross-site scripting vulnerability exists in wire-we... |
| CVE-2021-23395 | MEDIUM | 5.3 | 0.9% | Jun 15, 2021 | This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.pr... |
| CVE-2021-32684 | MEDIUM | 5.5 | 0.7% | Jun 14, 2021 | magento-scripts contains scripts and configuration used by Create Magento App, a zero-configuration tool-chain which all... |
| CVE-2021-34693 | MEDIUM | 5.5 | 0.5% | Jun 14, 2021 | net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack m... |
| CVE-2021-27887 | MEDIUM | 5.4 | 0.5% | Jun 14, 2021 | Cross-site Scripting (XSS) vulnerability in the main dashboard of Ellipse APM versions allows an authenticated user or i... |
| CVE-2021-0467 | MEDIUM | 6.8 | 0.1% | Jun 14, 2021 | In Chromecast bootROM, there is a possible out of bounds write due to an incorrect bounds check. This could lead to loca... |
| CVE-2021-21557 | MEDIUM | 6.7 | 0.3% | Jun 14, 2021 | Dell PowerEdge Server BIOS and select Dell Precision Rack BIOS contain an out-of-bounds array access vulnerability. A lo... |
| CVE-2021-21556 | MEDIUM | 6.7 | 0.3% | Jun 14, 2021 | Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer... |
| CVE-2021-21555 | MEDIUM | 6.7 | 0.3% | Jun 14, 2021 | Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer ... |
| CVE-2021-21554 | MEDIUM | 6.7 | 0.3% | Jun 14, 2021 | Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and, Dell Precision 7920 Rack Workstation BIOS co... |
| CVE-2021-24382 | MEDIUM | 5.4 | 0.7% | Jun 14, 2021 | The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it ... |
| CVE-2021-24360 | MEDIUM | 6.5 | 1.2% | Jun 14, 2021 | The Yes/No Chart WordPress plugin before 1.0.12 did not sanitise its sid shortcode parameter before using it in a SQL st... |
| CVE-2021-24359 | MEDIUM | 5.3 | 1.1% | Jun 14, 2021 | The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting ... |
| CVE-2021-24358 | MEDIUM | 6.1 | 2.3% | Jun 14, 2021 | The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a spe... |
| CVE-2021-24357 | MEDIUM | 5.4 | 0.6% | Jun 14, 2021 | In the Best Image Gallery & Responsive Photo Gallery – FooGallery WordPress plugin before 2.0.35, the Custom CSS field o... |
| CVE-2021-24355 | MEDIUM | 4.3 | 0.7% | Jun 14, 2021 | In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient... |
| CVE-2021-24351 | MEDIUM | 6.1 | 2.5% | Jun 14, 2021 | The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not p... |
| CVE-2021-24350 | MEDIUM | 6.1 | 1.3% | Jun 14, 2021 | The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabil... |
| CVE-2021-24349 | MEDIUM | 6.1 | 0.4% | Jun 14, 2021 | This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But fi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now