2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24679 | MEDIUM | 6.1 | 0.8% | Oct 4, 2021 | The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET paramete... |
| CVE-2021-24678 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which... |
| CVE-2021-24676 | MEDIUM | 6.1 | 0.8% | Oct 4, 2021 | The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back i... |
| CVE-2021-24673 | MEDIUM | 4.8 | 0.6% | Oct 4, 2021 | The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing... |
| CVE-2021-24654 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url val... |
| CVE-2021-24465 | HIGH | 8.1 | 1.1% | Oct 4, 2021 | The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery sh... |
| CVE-2021-22557 | HIGH | 7.8 | 1.6% | Oct 4, 2021 | SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within ... |
| CVE-2021-41869 | HIGH | 8.8 | 1.5% | Oct 4, 2021 | SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation. |
| CVE-2021-41322 | HIGH | 8.8 | 1.6% | Oct 4, 2021 | Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 dur... |
| CVE-2021-41285 | HIGH | 7.8 | 0.5% | Oct 4, 2021 | Ballistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vuln... |
| CVE-2021-40325 | HIGH | 7.5 | 1.3% | Oct 4, 2021 | Cobbler before 3.3.0 allows authorization bypass for modification of settings. |
| CVE-2021-40324 | HIGH | 7.5 | 68.6% | Oct 4, 2021 | Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. |
| CVE-2021-40323 | CRITICAL | 9.8 | 88.5% | Oct 4, 2021 | Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo... |
| CVE-2021-21706 | MEDIUM | 6.5 | 1.3% | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArch... |
| CVE-2021-21705 | MEDIUM | 5.3 | 1.9% | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality vi... |
| CVE-2021-21704 | MEDIUM | 5.9 | 1.7% | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, ... |
| CVE-2021-41861 | LOW | 3.3 | 0.3% | Oct 4, 2021 | The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different... |
| CVE-2021-41864 | HIGH | 7.8 | 0.4% | Oct 2, 2021 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to tri... |
| CVE-2021-41862 | CRITICAL | 9.8 | 1.9% | Oct 2, 2021 | AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (... |
| CVE-2021-38109 | MEDIUM | 5.5 | 1.5% | Oct 2, 2021 | Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An un... |
| CVE-2021-38108 | MEDIUM | 5.5 | 1.5% | Oct 2, 2021 | Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing... |
| CVE-2021-38107 | MEDIUM | 5.5 | 1.5% | Oct 2, 2021 | CdrCore.dll in Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
| CVE-2021-41847 | HIGH | 8.8 | 1.5% | Oct 1, 2021 | An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with ... |
| CVE-2021-38110 | HIGH | 7.8 | 2.1% | Oct 1, 2021 | Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsin... |
| CVE-2021-38106 | MEDIUM | 5.5 | 1.5% | Oct 1, 2021 | UAX200.dll in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now