2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36830 | MEDIUM | 4.8 | 0.4% | Sep 30, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress... |
| CVE-2021-45843 | MEDIUM | 6.1 | 0.7% | Sep 29, 2022 | glFusion CMS v1.7.9 is affected by a reflected Cross Site Scripting (XSS) vulnerability. The value of the title request ... |
| CVE-2021-45789 | MEDIUM | 6.5 | 0.9% | Sep 29, 2022 | An arbitrary file read vulnerability was found in Metersphere v1.15.4, where authenticated users can read any file on th... |
| CVE-2021-43403 | MEDIUM | 6.5 | 0.9% | Sep 29, 2022 | An issue was discovered in FusionPBX before 4.5.30. The log_viewer.php Log View page allows an authenticated user to cho... |
| CVE-2021-42049 | MEDIUM | 6.5 | 1.0% | Sep 29, 2022 | An issue was discovered in the Translate extension in MediaWiki through 1.36.2. Oversighters cannot undo revisions or ov... |
| CVE-2021-42048 | MEDIUM | 4.8 | 0.6% | Sep 29, 2022 | An issue was discovered in the Growth extension in MediaWiki through 1.36.2. Any admin can add arbitrary JavaScript code... |
| CVE-2021-42047 | MEDIUM | 5.4 | 0.6% | Sep 29, 2022 | An issue was discovered in the Growth extension in MediaWiki through 1.36.2. On any Wiki with the Mentor Dashboard featu... |
| CVE-2021-42046 | MEDIUM | 6.1 | 0.8% | Sep 29, 2022 | An issue was discovered in the GlobalWatchlist extension in MediaWiki through 1.36.2. The rev-deleted-user and ntimes me... |
| CVE-2021-42045 | MEDIUM | 5.4 | 0.6% | Sep 29, 2022 | An issue was discovered in SecurePoll in the Growth extension in MediaWiki through 1.36.2. Simple polls allow users to c... |
| CVE-2021-40695 | MEDIUM | 4.3 | 0.9% | Sep 29, 2022 | It was possible for a student to view their quiz grade before it had been released, using a quiz web service. |
| CVE-2021-40694 | MEDIUM | 4.9 | 0.9% | Sep 29, 2022 | Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP... |
| CVE-2021-40693 | MEDIUM | 6.5 | 0.8% | Sep 29, 2022 | An authentication bypass risk was identified in the external database authentication functionality, due to a type juggli... |
| CVE-2021-40692 | MEDIUM | 4.3 | 0.6% | Sep 29, 2022 | Insufficient capability checks made it possible for teachers to download users outside of their courses. |
| CVE-2021-40691 | MEDIUM | 4.3 | 0.7% | Sep 29, 2022 | A session hijack risk was identified in the Shibboleth authentication plugin. |
| CVE-2021-41434 | MEDIUM | 5.4 | 0.5% | Sep 28, 2022 | A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application tha... |
| CVE-2021-27862 | MEDIUM | 4.7 | 0.6% | Sep 27, 2022 | Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length ... |
| CVE-2021-27861 | MEDIUM | 4.7 | 0.6% | Sep 27, 2022 | Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length ... |
| CVE-2021-27854 | MEDIUM | 4.7 | 0.7% | Sep 27, 2022 | Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations of VLAN 0 headers, LLC/S... |
| CVE-2021-27853 | MEDIUM | 4.7 | 0.7% | Sep 27, 2022 | Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLA... |
| CVE-2021-28052 | MEDIUM | 4.9 | 0.7% | Sep 26, 2022 | A tenant administrator Hitachi Content Platform (HCP) may modify the configuration in another tenant without authorizati... |
| CVE-2021-41437 | MEDIUM | 6.5 | 0.8% | Sep 26, 2022 | An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to cr... |
| CVE-2021-45035 | MEDIUM | 5.9 | 0.4% | Sep 23, 2022 | Velneo vClient on its 28.1.3 version, does not correctly check the certificate of authenticity by default. This could al... |
| CVE-2021-3782 | MEDIUM | 6.6 | 0.3% | Sep 23, 2022 | An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. Th... |
| CVE-2021-27774 | MEDIUM | 5.4 | 0.3% | Sep 22, 2022 | User input included in error response, which could be used in a phishing attack. |
| CVE-2021-39190 | MEDIUM | 5.3 | 0.4% | Sep 22, 2022 | The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now