2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26588 | CRITICAL | 9.8 | 1.8% | Oct 11, 2021 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 S... |
| CVE-2021-25633 | HIGH | 7.5 | 0.7% | Oct 11, 2021 | LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt... |
| CVE-2021-22263 | MEDIUM | 6.5 | 1.1% | Oct 11, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr... |
| CVE-2021-20122 | HIGH | 7.2 | 6.5% | Oct 11, 2021 | The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vu... |
| CVE-2021-20121 | MEDIUM | 4 | 0.5% | Oct 11, 2021 | The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file rea... |
| CVE-2021-39317 | HIGH | 8.8 | 1.7% | Oct 11, 2021 | A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads... |
| CVE-2021-37123 | CRITICAL | 9.8 | 0.8% | Oct 11, 2021 | There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when ... |
| CVE-2021-27665 | HIGH | 7.5 | 1.5% | Oct 11, 2021 | An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a spe... |
| CVE-2021-27664 | CRITICAL | 9.8 | 1.5% | Oct 11, 2021 | Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVisi... |
| CVE-2021-0583 | HIGH | 7.3 | 0.1% | Oct 11, 2021 | In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjack... |
| CVE-2021-40541 | MEDIUM | 6.1 | 0.6% | Oct 11, 2021 | PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descri... |
| CVE-2021-40191 | MEDIUM | 5.4 | 0.5% | Oct 11, 2021 | Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all up... |
| CVE-2021-40543 | CRITICAL | 9.8 | 1.1% | Oct 11, 2021 | Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at ... |
| CVE-2021-40542 | MEDIUM | 6.1 | 3.0% | Oct 11, 2021 | Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja... |
| CVE-2021-29006 | MEDIUM | 6.5 | 7.0% | Oct 11, 2021 | rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any ... |
| CVE-2021-29005 | HIGH | 8.8 | 1.8% | Oct 11, 2021 | Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute ch... |
| CVE-2021-29004 | HIGH | 8.8 | 2.1% | Oct 11, 2021 | rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-... |
| CVE-2021-40888 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in... |
| CVE-2021-40887 | CRITICAL | 9.8 | 2.3% | Oct 11, 2021 | Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for ... |
| CVE-2021-40886 | MEDIUM | 6.5 | 1.4% | Oct 11, 2021 | Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2... |
| CVE-2021-40884 | HIGH | 8.1 | 0.9% | Oct 11, 2021 | Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids ... |
| CVE-2021-24737 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow mess... |
| CVE-2021-24720 | MEDIUM | 5.4 | 0.9% | Oct 11, 2021 | The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Sc... |
| CVE-2021-24719 | MEDIUM | 6.1 | 3.0% | Oct 11, 2021 | The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability... |
| CVE-2021-24712 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new cal... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now