2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39931 | MEDIUM | 4.3 | 0.9% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions start... |
| CVE-2021-39930 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 1... |
| CVE-2021-39919 | MEDIUM | 4.4 | 0.3% | Dec 13, 2021 | In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all ... |
| CVE-2021-39918 | MEDIUM | 4.3 | 0.7% | Dec 13, 2021 | Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from... |
| CVE-2021-39917 | MEDIUM | 6.5 | 1.3% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions start... |
| CVE-2021-39916 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the conf... |
| CVE-2021-39915 | MEDIUM | 5.3 | 1.1% | Dec 13, 2021 | Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all ... |
| CVE-2021-39910 | MEDIUM | 4.3 | 1.0% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions start... |
| CVE-2021-22279 | CRITICAL | 9.8 | 1.4% | Dec 13, 2021 | A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and mod... |
| CVE-2021-44966 | CRITICAL | 9.8 | 2.1% | Dec 13, 2021 | SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An ... |
| CVE-2021-44965 | HIGH | 7.5 | 2.2% | Dec 13, 2021 | Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 Th... |
| CVE-2021-36169 | MEDIUM | 6 | 0.3% | Dec 13, 2021 | A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unaut... |
| CVE-2021-43117 | CRITICAL | 9.8 | 2.1% | Dec 13, 2021 | fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access. |
| CVE-2021-42549 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenti... |
| CVE-2021-42548 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows una... |
| CVE-2021-42547 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unau... |
| CVE-2021-42546 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unau... |
| CVE-2021-24972 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users... |
| CVE-2021-24970 | HIGH | 7.2 | 5.9% | Dec 13, 2021 | The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using... |
| CVE-2021-24955 | MEDIUM | 6.1 | 1.0% | Dec 13, 2021 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data para... |
| CVE-2021-24954 | MEDIUM | 6.1 | 1.0% | Dec 13, 2021 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape ... |
| CVE-2021-24951 | CRITICAL | 9.8 | 1.6% | Dec 13, 2021 | The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in ... |
| CVE-2021-24946 | CRITICAL | 9.8 | 73.4% | Dec 13, 2021 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before usi... |
| CVE-2021-24945 | HIGH | 8 | 0.6% | Dec 13, 2021 | The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the l... |
| CVE-2021-24932 | MEDIUM | 6.1 | 0.8% | Dec 13, 2021 | The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id par... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now