2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33090 | HIGH | 7.8 | 0.2% | Nov 17, 2021 | Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC... |
| CVE-2021-33089 | HIGH | 7.8 | 0.2% | Nov 17, 2021 | Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE,... |
| CVE-2021-33088 | HIGH | 7.8 | 0.2% | Nov 17, 2021 | Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack bef... |
| CVE-2021-33087 | MEDIUM | 5.5 | 0.2% | Nov 17, 2021 | Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before versio... |
| CVE-2021-33086 | MEDIUM | 5.5 | 0.2% | Nov 17, 2021 | Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of s... |
| CVE-2021-0121 | HIGH | 7.8 | 0.2% | Nov 17, 2021 | Improper access control in the installer for some Intel(R) Iris(R) Xe MAX Dedicated Graphics Drivers for Windows 10 befo... |
| CVE-2021-0096 | HIGH | 7.8 | 0.2% | Nov 17, 2021 | Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN,... |
| CVE-2021-42362 | HIGH | 8.8 | 79.8% | Nov 17, 2021 | The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type... |
| CVE-2021-42360 | MEDIUM | 5.4 | 0.6% | Nov 17, 2021 | On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab... |
| CVE-2021-35528 | HIGH | 7.1 | 0.3% | Nov 17, 2021 | Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Opera... |
| CVE-2021-33481 | HIGH | 7.8 | 1.1% | Nov 17, 2021 | A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in try_to_divide_boxes() in pgm... |
| CVE-2021-33480 | MEDIUM | 5.5 | 1.0% | Nov 17, 2021 | An use-after-free vulnerability was discovered in gocr through 0.53-20200802 in context_correction() in pgm2asc.c. |
| CVE-2021-33479 | HIGH | 7.8 | 1.1% | Nov 17, 2021 | A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in measure_pitch() in pgm2asc.c... |
| CVE-2021-43977 | MEDIUM | 6.1 | 0.6% | Nov 17, 2021 | SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS. |
| CVE-2021-43976 | MEDIUM | 4.6 | 0.6% | Nov 17, 2021 | In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (w... |
| CVE-2021-43975 | MEDIUM | 6.7 | 0.5% | Nov 17, 2021 | In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_uti... |
| CVE-2021-32234 | CRITICAL | 9.8 | 2.1% | Nov 17, 2021 | SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution. |
| CVE-2021-40745 | HIGH | 7.5 | 3.6% | Nov 17, 2021 | Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arb... |
| CVE-2021-42250 | MEDIUM | 6.5 | 1.8% | Nov 17, 2021 | Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to f... |
| CVE-2021-38959 | MEDIUM | 5.5 | 0.2% | Nov 17, 2021 | IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of s... |
| CVE-2021-29861 | MEDIUM | 6.2 | 0.3% | Nov 17, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensi... |
| CVE-2021-29860 | MEDIUM | 6.2 | 0.3% | Nov 17, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library ... |
| CVE-2021-42955 | HIGH | 7.8 | 0.4% | Nov 17, 2021 | Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password... |
| CVE-2021-42954 | HIGH | 7.8 | 0.4% | Nov 17, 2021 | Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. Th... |
| CVE-2021-42956 | HIGH | 8.8 | 0.6% | Nov 17, 2021 | Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now