2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29424 | HIGH | 7.5 | 2.0% | Apr 6, 2021 | The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of... |
| CVE-2021-30130 | HIGH | 7.5 | 1.1% | Apr 6, 2021 | phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification. |
| CVE-2021-28142 | HIGH | 8.8 | 5.8% | Apr 6, 2021 | CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete." |
| CVE-2021-28874 | HIGH | 7.8 | 1.0% | Apr 6, 2021 | SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode ... |
| CVE-2021-28075 | HIGH | 7.5 | 1.0% | Apr 6, 2021 | iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to ob... |
| CVE-2021-27343 | HIGH | 7.5 | 1.7% | Apr 6, 2021 | SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent).... |
| CVE-2021-28172 | HIGH | 7.5 | 1.8% | Apr 6, 2021 | There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers ... |
| CVE-2021-30163 | HIGH | 7.5 | 1.2% | Apr 6, 2021 | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal ... |
| CVE-2021-30162 | HIGH | 7.1 | 0.1% | Apr 6, 2021 | An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS servic... |
| CVE-2021-28204 | HIGH | 7.2 | 2.0% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter th... |
| CVE-2021-28203 | HIGH | 7.2 | 2.0% | Apr 6, 2021 | The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As o... |
| CVE-2021-30141 | HIGH | 7.5 | 1.5% | Apr 5, 2021 | Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as... |
| CVE-2021-20305 | HIGH | 8.1 | 1.6% | Apr 5, 2021 | A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, ED... |
| CVE-2021-24209 | HIGH | 7.2 | 23.8% | Apr 5, 2021 | The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due ... |
| CVE-2021-24184 | HIGH | 8.8 | 1.4% | Apr 5, 2021 | Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprot... |
| CVE-2021-24174 | HIGH | 8.1 | 3.2% | Apr 5, 2021 | The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in ... |
| CVE-2021-24170 | HIGH | 7.5 | 4.8% | Apr 5, 2021 | The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than... |
| CVE-2021-24167 | HIGH | 7.5 | 1.4% | Apr 5, 2021 | When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send ... |
| CVE-2021-24163 | HIGH | 8.8 | 1.4% | Apr 5, 2021 | The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it ha... |
| CVE-2021-24162 | HIGH | 8.8 | 0.8% | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini... |
| CVE-2021-24161 | HIGH | 8.8 | 1.2% | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini... |
| CVE-2021-24160 | HIGH | 8.8 | 8.4% | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing ma... |
| CVE-2021-24159 | HIGH | 8.8 | 0.6% | Apr 5, 2021 | Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a reques... |
| CVE-2021-24155 | HIGH | 7.2 | 83.7% | Apr 5, 2021 | The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported fi... |
| CVE-2021-24150 | HIGH | 7.5 | 4.4% | Apr 5, 2021 | The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now