2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32816 | HIGH | 7.5 | 1.0% | May 14, 2021 | ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Clien... |
| CVE-2021-20393 | HIGH | 7.5 | 1.4% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information whe... |
| CVE-2021-24280 | HIGH | 8.8 | 2.0% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could... |
| CVE-2021-24278 | HIGH | 7.5 | 7.4% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce ... |
| CVE-2021-24195 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer ... |
| CVE-2021-24194 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit F... |
| CVE-2021-24193 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time ... |
| CVE-2021-24192 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plu... |
| CVE-2021-24191 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site... |
| CVE-2021-24190 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Ma... |
| CVE-2021-24189 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptc... |
| CVE-2021-24188 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection... |
| CVE-2021-30183 | HIGH | 7.5 | 0.9% | May 14, 2021 | Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when runni... |
| CVE-2021-32051 | HIGH | 7.5 | 2.2% | May 14, 2021 | Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id par... |
| CVE-2021-31922 | HIGH | 7.5 | 1.0% | May 14, 2021 | An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to s... |
| CVE-2021-29510 | HIGH | 7.5 | 1.0% | May 13, 2021 | Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'i... |
| CVE-2021-27413 | HIGH | 7.8 | 10.0% | May 13, 2021 | Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based b... |
| CVE-2021-22140 | HIGH | 7.5 | 1.3% | May 13, 2021 | Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the A... |
| CVE-2021-32920 | HIGH | 7.5 | 2.3% | May 13, 2021 | Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests. |
| CVE-2021-32919 | HIGH | 7.5 | 1.4% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enab... |
| CVE-2021-32918 | HIGH | 7.5 | 2.1% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-s... |
| CVE-2021-20181 | HIGH | 7.5 | 0.3% | May 13, 2021 | A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a ... |
| CVE-2021-3528 | HIGH | 8.8 | 0.9% | May 13, 2021 | A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator ... |
| CVE-2021-20025 | HIGH | 7.8 | 0.4% | May 13, 2021 | SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password... |
| CVE-2021-25693 | HIGH | 7.5 | 1.0% | May 13, 2021 | An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer derefere... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now