2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36350 | HIGH | 7.5 | 1.1% | Dec 21, 2021 | Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authen... |
| CVE-2021-36341 | MEDIUM | 5.5 | 0.2% | Dec 21, 2021 | Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated... |
| CVE-2021-36337 | HIGH | 7.4 | 0.4% | Dec 21, 2021 | Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 whi... |
| CVE-2021-36336 | CRITICAL | 9.8 | 1.7% | Dec 21, 2021 | Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticat... |
| CVE-2021-36318 | MEDIUM | 6.7 | 0.2% | Dec 21, 2021 | Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged... |
| CVE-2021-36317 | MEDIUM | 6.7 | 0.2% | Dec 21, 2021 | Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacke... |
| CVE-2021-36316 | HIGH | 7.2 | 0.7% | Dec 21, 2021 | Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability ... |
| CVE-2021-45091 | MEDIUM | 4.3 | 0.6% | Dec 21, 2021 | Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control. |
| CVE-2021-45090 | CRITICAL | 9.8 | 2.9% | Dec 21, 2021 | Stormshield Endpoint Security before 2.1.2 allows remote code execution. |
| CVE-2021-45089 | MEDIUM | 5.2 | 0.3% | Dec 21, 2021 | Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control. |
| CVE-2021-4139 | CRITICAL | 9 | 0.9% | Dec 21, 2021 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-45255 | CRITICAL | 9.8 | 1.5% | Dec 21, 2021 | The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payl... |
| CVE-2021-45253 | CRITICAL | 9.8 | 1.2% | Dec 21, 2021 | The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL inje... |
| CVE-2021-45252 | CRITICAL | 9.8 | 1.2% | Dec 21, 2021 | Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications... |
| CVE-2021-24981 | HIGH | 7.5 | 0.8% | Dec 21, 2021 | The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leadi... |
| CVE-2021-24956 | MEDIUM | 6.1 | 1.7% | Dec 21, 2021 | The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sSh... |
| CVE-2021-24941 | MEDIUM | 6.1 | 0.8% | Dec 21, 2021 | The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape th... |
| CVE-2021-24907 | MEDIUM | 6.1 | 0.9% | Dec 21, 2021 | The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter befo... |
| CVE-2021-24849 | CRITICAL | 9.8 | 8.5% | Dec 21, 2021 | The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate... |
| CVE-2021-24846 | HIGH | 8.8 | 1.3% | Dec 21, 2021 | The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_a... |
| CVE-2021-24750 | HIGH | 8.8 | 38.6% | Dec 21, 2021 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refU... |
| CVE-2021-24739 | HIGH | 8.1 | 1.0% | Dec 21, 2021 | The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb... |
| CVE-2021-24738 | MEDIUM | 5.4 | 0.6% | Dec 21, 2021 | The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which co... |
| CVE-2021-24578 | MEDIUM | 6.1 | 0.8% | Dec 21, 2021 | The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting bac... |
| CVE-2021-45451 | HIGH | 7.5 | 0.8% | Dec 21, 2021 | In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now