2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43584 | MEDIUM | 4.8 | 1.2% | Jan 24, 2024 | DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Age... |
| CVE-2021-33630 | MEDIUM | 5.5 | 0.3% | Jan 18, 2024 | NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This ... |
| CVE-2021-4227 | MEDIUM | 5.3 | 0.6% | Jan 16, 2024 | The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source e... |
| CVE-2021-25117 | MEDIUM | 4.8 | 0.2% | Jan 16, 2024 | The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options pag... |
| CVE-2021-24870 | MEDIUM | 6.1 | 0.3% | Jan 16, 2024 | The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action,... |
| CVE-2021-24567 | MEDIUM | 5.4 | 0.5% | Jan 16, 2024 | The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it... |
| CVE-2021-24559 | MEDIUM | 5.4 | 0.2% | Jan 16, 2024 | The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, ... |
| CVE-2021-24433 | MEDIUM | 5.4 | 0.4% | Jan 16, 2024 | The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "... |
| CVE-2021-24432 | MEDIUM | 6.1 | 0.4% | Jan 16, 2024 | The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it i... |
| CVE-2021-38927 | MEDIUM | 6.1 | 0.3% | Dec 25, 2023 | IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS... |
| CVE-2021-42794 | MEDIUM | 5.3 | 1.2% | Dec 16, 2023 | An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a ... |
| CVE-2021-35975 | MEDIUM | 5.3 | 1.1% | Nov 30, 2023 | Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius... |
| CVE-2021-36806 | MEDIUM | 6.1 | 0.4% | Nov 30, 2023 | A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sop... |
| CVE-2021-39008 | MEDIUM | 4.9 | 0.6% | Nov 23, 2023 | IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to mi... |
| CVE-2021-22143 | MEDIUM | 4.3 | 0.6% | Nov 22, 2023 | The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err... |
| CVE-2021-22151 | MEDIUM | 4.3 | 0.7% | Nov 22, 2023 | It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a m... |
| CVE-2021-46766 | MEDIUM | 5.5 | 0.2% | Nov 14, 2023 | Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP ... |
| CVE-2021-46758 | MEDIUM | 6.1 | 0.3% | Nov 14, 2023 | Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to rea... |
| CVE-2021-46748 | MEDIUM | 5.5 | 0.2% | Nov 14, 2023 | Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds... |
| CVE-2021-26345 | MEDIUM | 4.9 | 0.4% | Nov 14, 2023 | Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-b... |
| CVE-2021-4431 | MEDIUM | 6.1 | 0.6% | Nov 7, 2023 | A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of ... |
| CVE-2021-25736 | MEDIUM | 6.3 | 0.9% | Oct 30, 2023 | Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*... |
| CVE-2021-33638 | MEDIUM | 6.5 | 0.2% | Oct 29, 2023 | When the isula cp command is used to copy files from a container to a host machine and the container is controlled by a... |
| CVE-2021-33637 | MEDIUM | 6.5 | 0.2% | Oct 29, 2023 | When the isula export command is used to export a container to an image and the container is controlled by an attacker,... |
| CVE-2021-33634 | MEDIUM | 5.5 | 0.2% | Oct 29, 2023 | iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now