2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31693 | MEDIUM | 6.1 | 0.4% | Nov 29, 2022 | The 10Web Photo Gallery plugin through 1.5.68 for WordPress allows XSS via album_gallery_id_0, bwg_album_search_0, and t... |
| CVE-2021-25059 | MEDIUM | 4.3 | 0.6% | Nov 28, 2022 | The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to acces... |
| CVE-2021-35246 | MEDIUM | 5.3 | 0.3% | Nov 23, 2022 | The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a ... |
| CVE-2021-37936 | MEDIUM | 5.4 | 0.5% | Nov 18, 2022 | It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an ... |
| CVE-2021-31739 | MEDIUM | 6.1 | 0.4% | Nov 18, 2022 | The SEPPmail solution is vulnerable to a Cross-Site Scripting vulnerability (XSS), because user input is not correctly e... |
| CVE-2021-22141 | MEDIUM | 6.1 | 0.5% | Nov 18, 2022 | An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously cr... |
| CVE-2021-36905 | MEDIUM | 5.4 | 0.4% | Nov 17, 2022 | Multiple Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Quiz And Survey Master plugin <= 7.3.... |
| CVE-2021-31608 | MEDIUM | 4.3 | 0.4% | Nov 17, 2022 | Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control. |
| CVE-2021-33897 | MEDIUM | 5.5 | 0.2% | Nov 17, 2022 | A buffer overflow in Synthesia before 10.7.5567, when a non-Latin locale is used, allows user-assisted attackers to caus... |
| CVE-2021-4241 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | A vulnerability, which was classified as problematic, was found in phpservermon. Affected is the function setUserLoggedI... |
| CVE-2021-4240 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | A vulnerability, which was classified as problematic, was found in phpservermon. This affects the function generatePassw... |
| CVE-2021-40272 | MEDIUM | 6.1 | 1.0% | Nov 14, 2022 | OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS). |
| CVE-2021-38828 | MEDIUM | 5.3 | 0.3% | Nov 14, 2022 | Xiongmai Camera XM-JPR2-LX V4.02.R12.A6420987.10002.147502.00000 is vulnerable to plain-text traffic sniffing. |
| CVE-2021-33164 | MEDIUM | 6.7 | 0.2% | Nov 11, 2022 | Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user... |
| CVE-2021-33159 | MEDIUM | 6.7 | 0.2% | Nov 11, 2022 | Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.... |
| CVE-2021-26251 | MEDIUM | 6.5 | 0.6% | Nov 11, 2022 | Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potent... |
| CVE-2021-0185 | MEDIUM | 6.7 | 0.2% | Nov 10, 2022 | Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a ... |
| CVE-2021-40289 | MEDIUM | 6.1 | 0.5% | Nov 10, 2022 | mm-wki v0.2.1 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2021-26393 | MEDIUM | 5.5 | 0.2% | Nov 9, 2022 | Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authentic... |
| CVE-2021-34577 | MEDIUM | 6.5 | 0.3% | Nov 9, 2022 | In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded sh... |
| CVE-2021-40303 | MEDIUM | 5.4 | 0.5% | Nov 8, 2022 | perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile. |
| CVE-2021-42205 | MEDIUM | 4.7 | 0.3% | Nov 7, 2022 | ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows loca... |
| CVE-2021-39473 | MEDIUM | 5.4 | 0.6% | Nov 4, 2022 | Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and conta... |
| CVE-2021-39432 | MEDIUM | 6.5 | 0.7% | Nov 4, 2022 | diplib v3.0.0 is vulnerable to Double Free. |
| CVE-2021-39077 | MEDIUM | 4.4 | 0.1% | Nov 3, 2022 | IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now