2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43584MEDIUM4.8DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Age...
CVE-2021-33630MEDIUM5.5NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This ...
CVE-2021-4227MEDIUM5.3The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source e...
CVE-2021-25117MEDIUM4.8The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options pag...
CVE-2021-24870MEDIUM6.1The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action,...
CVE-2021-24567MEDIUM5.4The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it...
CVE-2021-24559MEDIUM5.4The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, ...
CVE-2021-24433MEDIUM5.4The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "...
CVE-2021-24432MEDIUM6.1The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it i...
CVE-2021-38927MEDIUM6.1IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS...
CVE-2021-42794MEDIUM5.3An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a ...
CVE-2021-35975MEDIUM5.3Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius...
CVE-2021-36806MEDIUM6.1 A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sop...
CVE-2021-39008MEDIUM4.9 IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to mi...
CVE-2021-22143MEDIUM4.3The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err...
CVE-2021-22151MEDIUM4.3It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a m...
CVE-2021-46766MEDIUM5.5Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP ...
CVE-2021-46758MEDIUM6.1Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to rea...
CVE-2021-46748MEDIUM5.5Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds...
CVE-2021-26345MEDIUM4.9Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-b...
CVE-2021-4431MEDIUM6.1A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of ...
CVE-2021-25736MEDIUM6.3Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*...
CVE-2021-33638MEDIUM6.5 When the isula cp command is used to copy files from a container to a host machine and the container is controlled by a...
CVE-2021-33637MEDIUM6.5 When the isula export command is used to export a container to an image and the container is controlled by an attacker,...
CVE-2021-33634MEDIUM5.5iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now