2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3878 | CRITICAL | 9.8 | 1.8% | Oct 15, 2021 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2021-3875 | MEDIUM | 5.5 | 1.4% | Oct 15, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3874 | MEDIUM | 6.5 | 1.2% | Oct 15, 2021 | bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2021-37739 | HIGH | 7.2 | 2.8% | Oct 15, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas... |
| CVE-2021-37738 | HIGH | 7.5 | 1.2% | Oct 15, 2021 | A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ... |
| CVE-2021-39349 | MEDIUM | 4.8 | 1.1% | Oct 15, 2021 | The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation an... |
| CVE-2021-39345 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitizat... |
| CVE-2021-39344 | MEDIUM | 4.8 | 1.0% | Oct 15, 2021 | The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation... |
| CVE-2021-39338 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation... |
| CVE-2021-39337 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa... |
| CVE-2021-39336 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and s... |
| CVE-2021-39335 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validat... |
| CVE-2021-39334 | MEDIUM | 4.8 | 0.9% | Oct 15, 2021 | The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-39332 | MEDIUM | 4.8 | 0.5% | Oct 15, 2021 | The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ... |
| CVE-2021-38431 | MEDIUM | 4.3 | 0.7% | Oct 15, 2021 | An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose proj... |
| CVE-2021-37737 | HIGH | 8.8 | 1.1% | Oct 15, 2021 | A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manag... |
| CVE-2021-37736 | CRITICAL | 9.8 | 1.5% | Oct 15, 2021 | A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Poli... |
| CVE-2021-42336 | MEDIUM | 4.3 | 0.8% | Oct 15, 2021 | The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remot... |
| CVE-2021-42335 | MEDIUM | 5.4 | 0.6% | Oct 15, 2021 | Easytest bulletin board management function of online learning platform does not filter special characters. After obtain... |
| CVE-2021-42334 | HIGH | 8.8 | 1.1% | Oct 15, 2021 | The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL... |
| CVE-2021-42333 | HIGH | 8.8 | 1.1% | Oct 15, 2021 | The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL c... |
| CVE-2021-42332 | MEDIUM | 4.3 | 0.7% | Oct 15, 2021 | The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s priv... |
| CVE-2021-42331 | MEDIUM | 5.4 | 0.6% | Oct 15, 2021 | The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’... |
| CVE-2021-42330 | HIGH | 8.8 | 0.9% | Oct 15, 2021 | The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user... |
| CVE-2021-42329 | MEDIUM | 5.4 | 0.6% | Oct 15, 2021 | The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title p... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now