2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39356 | MEDIUM | 4.8 | 1.0% | Oct 21, 2021 | The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation a... |
| CVE-2021-39354 | MEDIUM | 4.8 | 0.9% | Oct 21, 2021 | The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end... |
| CVE-2021-39352 | HIGH | 7.2 | 56.6% | Oct 21, 2021 | The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found... |
| CVE-2021-39348 | MEDIUM | 4.8 | 5.0% | Oct 21, 2021 | The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom... |
| CVE-2021-39328 | MEDIUM | 4.8 | 0.9% | Oct 21, 2021 | The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $... |
| CVE-2021-39321 | HIGH | 8.8 | 2.0% | Oct 21, 2021 | Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_... |
| CVE-2021-22034 | HIGH | 7.5 | 1.0% | Oct 21, 2021 | Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability. |
| CVE-2021-42716 | HIGH | 7.1 | 1.4% | Oct 21, 2021 | An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when c... |
| CVE-2021-42715 | MEDIUM | 5.5 | 1.2% | Oct 21, 2021 | An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines ... |
| CVE-2021-41160 | HIGH | 8.8 | 1.6% | Oct 21, 2021 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected ve... |
| CVE-2021-41159 | HIGH | 8.8 | 1.3% | Oct 21, 2021 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP cl... |
| CVE-2021-41146 | HIGH | 8.8 | 1.4% | Oct 21, 2021 | qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows... |
| CVE-2021-35228 | MEDIUM | 4.7 | 0.6% | Oct 21, 2021 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from header... |
| CVE-2021-35227 | HIGH | 7.8 | 0.5% | Oct 21, 2021 | The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available. |
| CVE-2021-35225 | MEDIUM | 6.4 | 0.8% | Oct 21, 2021 | Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath S... |
| CVE-2021-42327 | MEDIUM | 6.7 | 0.8% | Oct 21, 2021 | dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 ... |
| CVE-2021-29883 | MEDIUM | 4.3 | 0.5% | Oct 21, 2021 | IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on... |
| CVE-2021-29873 | HIGH | 8.1 | 1.5% | Oct 21, 2021 | IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service... |
| CVE-2021-28496 | MEDIUM | 6.5 | 0.4% | Oct 21, 2021 | On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the pass... |
| CVE-2021-20120 | HIGH | 8.8 | 0.5% | Oct 21, 2021 | The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery... |
| CVE-2021-28975 | MEDIUM | 6.1 | 0.9% | Oct 21, 2021 | WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted serve... |
| CVE-2021-42740 | CRITICAL | 9.8 | 4.3% | Oct 21, 2021 | The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metach... |
| CVE-2021-35512 | MEDIUM | 6.5 | 1.6% | Oct 21, 2021 | An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. |
| CVE-2021-41792 | MEDIUM | 5.3 | 0.8% | Oct 21, 2021 | An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-tran... |
| CVE-2021-41791 | MEDIUM | 5.4 | 0.5% | Oct 21, 2021 | An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An ev... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now