2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39341 | HIGH | 8.2 | 23.3% | Nov 1, 2021 | The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due... |
| CVE-2021-39340 | MEDIUM | 4.8 | 0.9% | Nov 1, 2021 | The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and ... |
| CVE-2021-39333 | HIGH | 8.1 | 1.0% | Nov 1, 2021 | The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce whic... |
| CVE-2021-38356 | MEDIUM | 6.1 | 0.8% | Nov 1, 2021 | The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting ... |
| CVE-2021-20136 | CRITICAL | 9.8 | 10.5% | Nov 1, 2021 | ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configurati... |
| CVE-2021-31849 | HIGH | 7.2 | 1.0% | Nov 1, 2021 | SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacke... |
| CVE-2021-31848 | MEDIUM | 6.1 | 0.8% | Nov 1, 2021 | Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a r... |
| CVE-2021-42917 | MEDIUM | 5.5 | 1.9% | Nov 1, 2021 | Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper len... |
| CVE-2021-26740 | CRITICAL | 9.8 | 1.6% | Nov 1, 2021 | Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code. |
| CVE-2021-26739 | CRITICAL | 9.8 | 1.6% | Nov 1, 2021 | SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attri... |
| CVE-2021-38847 | HIGH | 8.8 | 1.3% | Nov 1, 2021 | S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Adm... |
| CVE-2021-3705 | CRITICAL | 9.8 | 1.8% | Nov 1, 2021 | Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow an unauthori... |
| CVE-2021-3704 | HIGH | 7.5 | 1.4% | Nov 1, 2021 | Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow a Denial of ... |
| CVE-2021-3440 | HIGH | 7.8 | 0.3% | Nov 1, 2021 | HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevati... |
| CVE-2021-29213 | MEDIUM | 6.7 | 0.3% | Nov 1, 2021 | A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProL... |
| CVE-2021-29212 | CRITICAL | 9.8 | 13.5% | Nov 1, 2021 | A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versio... |
| CVE-2021-27005 | HIGH | 7.5 | 1.2% | Nov 1, 2021 | Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerabili... |
| CVE-2021-27004 | MEDIUM | 5.5 | 0.2% | Nov 1, 2021 | System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which c... |
| CVE-2021-22564 | MEDIUM | 5.5 | 0.3% | Nov 1, 2021 | For certain valid JPEG XL images with a size slightly larger than an integer number of groups (256x256 pixels) when proc... |
| CVE-2021-22563 | MEDIUM | 4.4 | 0.3% | Nov 1, 2021 | Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering sp... |
| CVE-2021-42557 | HIGH | 7.5 | 2.2% | Nov 1, 2021 | In Jeedom through 4.1.19, a bug allows a remote attacker to bypass API access and retrieve users credentials. |
| CVE-2021-25878 | MEDIUM | 6.1 | 1.1% | Nov 1, 2021 | AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoN... |
| CVE-2021-25877 | HIGH | 7.2 | 3.1% | Nov 1, 2021 | AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write f... |
| CVE-2021-25876 | MEDIUM | 6.1 | 1.1% | Nov 1, 2021 | AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which... |
| CVE-2021-25875 | MEDIUM | 6.1 | 1.1% | Nov 1, 2021 | AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now