2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22022 | MEDIUM | 4.9 | 1.1% | Aug 30, 2021 | The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor ... |
| CVE-2021-21774 | — | — | — | Aug 30, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21773. Reason: This candidate is a reservation d... |
| CVE-2021-21741 | CRITICAL | 9.8 | 1.9% | Aug 30, 2021 | There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by defaul... |
| CVE-2021-29743 | MEDIUM | 5.4 | 0.5% | Aug 30, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows user... |
| CVE-2021-29728 | MEDIUM | 4.9 | 1.0% | Aug 30, 2021 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryp... |
| CVE-2021-29723 | HIGH | 7.5 | 0.9% | Aug 30, 2021 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou... |
| CVE-2021-29722 | HIGH | 7.5 | 0.9% | Aug 30, 2021 | IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou... |
| CVE-2021-27913 | LOW | 3.5 | 0.5% | Aug 30, 2021 | The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature bei... |
| CVE-2021-27912 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inl... |
| CVE-2021-27911 | MEDIUM | 6.1 | 0.6% | Aug 30, 2021 | Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name an... |
| CVE-2021-27910 | MEDIUM | 6.1 | 0.7% | Aug 30, 2021 | Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management ca... |
| CVE-2021-27909 | MEDIUM | 6.1 | 4.1% | Aug 30, 2021 | For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerab... |
| CVE-2021-37911 | HIGH | 8.8 | 0.6% | Aug 30, 2021 | The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attacke... |
| CVE-2021-24667 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.... |
| CVE-2021-24665 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users wit... |
| CVE-2021-24593 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting ... |
| CVE-2021-24592 | MEDIUM | 4.8 | 0.6% | Aug 30, 2021 | The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron... |
| CVE-2021-24581 | HIGH | 8.8 | 4.1% | Aug 30, 2021 | The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting ... |
| CVE-2021-24580 | HIGH | 8.8 | 1.4% | Aug 30, 2021 | The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard ... |
| CVE-2021-24579 | HIGH | 8.8 | 8.2% | Aug 30, 2021 | The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unseria... |
| CVE-2021-24528 | MEDIUM | 5.4 | 0.6% | Aug 30, 2021 | The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, n... |
| CVE-2021-24438 | MEDIUM | 6.1 | 0.8% | Aug 30, 2021 | The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' p... |
| CVE-2021-24437 | MEDIUM | 6.1 | 0.8% | Aug 30, 2021 | The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter bef... |
| CVE-2021-25958 | HIGH | 7.5 | 2.6% | Aug 30, 2021 | In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations ... |
| CVE-2021-39117 | MEDIUM | 4.8 | 0.6% | Aug 30, 2021 | The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now