2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3645 | CRITICAL | 9.8 | 1.4% | Sep 10, 2021 | merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-34346 | CRITICAL | 9.8 | 1.5% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite... |
| CVE-2021-34345 | CRITICAL | 9.8 | 1.5% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite... |
| CVE-2021-34344 | CRITICAL | 9.8 | 1.5% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulne... |
| CVE-2021-34343 | HIGH | 7.2 | 1.9% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If expl... |
| CVE-2021-28816 | HIGH | 8.8 | 0.9% | Sep 10, 2021 | A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If expl... |
| CVE-2021-28813 | HIGH | 7.5 | 1.1% | Sep 10, 2021 | A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP... |
| CVE-2021-40839 | HIGH | 7.5 | 5.4% | Sep 10, 2021 | The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabl... |
| CVE-2021-39206 | HIGH | 8.6 | 1.4% | Sep 9, 2021 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization re... |
| CVE-2021-39204 | HIGH | 7.5 | 1.6% | Sep 9, 2021 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting... |
| CVE-2021-39203 | MEDIUM | 6.5 | 0.9% | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database... |
| CVE-2021-39202 | MEDIUM | 5.4 | 0.8% | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database... |
| CVE-2021-39201 | MEDIUM | 5.4 | 1.5% | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database... |
| CVE-2021-39200 | MEDIUM | 5.3 | 2.1% | Sep 9, 2021 | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database... |
| CVE-2021-39162 | HIGH | 8.6 | 1.6% | Sep 9, 2021 | Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if a... |
| CVE-2021-32724 | CRITICAL | 9.9 | 2.3% | Sep 9, 2021 | check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [... |
| CVE-2021-38325 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter fou... |
| CVE-2021-38324 | HIGH | 7.5 | 1.7% | Sep 9, 2021 | The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shor... |
| CVE-2021-38323 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the... |
| CVE-2021-38322 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_... |
| CVE-2021-38321 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter ... |
| CVE-2021-38320 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_S... |
| CVE-2021-38319 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_S... |
| CVE-2021-38318 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cov... |
| CVE-2021-38317 | MEDIUM | 6.1 | 0.9% | Sep 9, 2021 | The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now