2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37618 | MEDIUM | 5.5 | 1.0% | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-37616 | MEDIUM | 5.5 | 1.0% | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-37623 | MEDIUM | 5.5 | 1.1% | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-34334 | MEDIUM | 5.5 | 1.1% | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-32815 | MEDIUM | 5.5 | 1.1% | Aug 9, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-25954 | MEDIUM | 4.3 | 0.7% | Aug 9, 2021 | In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthor... |
| CVE-2021-29714 | MEDIUM | 6.5 | 1.0% | Aug 9, 2021 | IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation.... |
| CVE-2021-21740 | LOW | 2.4 | 0.4% | Aug 9, 2021 | There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The a... |
| CVE-2021-20349 | MEDIUM | 5.3 | 0.3% | Aug 9, 2021 | IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds chec... |
| CVE-2021-33256 | HIGH | 8.8 | 79.0% | Aug 9, 2021 | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be e... |
| CVE-2021-37788 | MEDIUM | 5.4 | 1.5% | Aug 9, 2021 | A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect t... |
| CVE-2021-37573 | MEDIUM | 6.1 | 3.4% | Aug 9, 2021 | A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS... |
| CVE-2021-36798 | HIGH | 7.5 | 4.3% | Aug 9, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allow... |
| CVE-2021-34661 | MEDIUM | 4.7 | 0.5% | Aug 9, 2021 | The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function fou... |
| CVE-2021-34660 | MEDIUM | 6.1 | 0.8% | Aug 9, 2021 | The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in... |
| CVE-2021-22910 | CRITICAL | 9.8 | 2.3% | Aug 9, 2021 | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an ... |
| CVE-2021-38290 | HIGH | 8.1 | 1.3% | Aug 9, 2021 | A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel... |
| CVE-2021-37215 | MEDIUM | 4.3 | 0.7% | Aug 9, 2021 | The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being aut... |
| CVE-2021-37214 | HIGH | 8.8 | 1.1% | Aug 9, 2021 | The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authen... |
| CVE-2021-37213 | MEDIUM | 4.3 | 0.8% | Aug 9, 2021 | The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authentica... |
| CVE-2021-37212 | MEDIUM | 5.4 | 0.6% | Aug 9, 2021 | The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated... |
| CVE-2021-37211 | MEDIUM | 5.4 | 0.5% | Aug 9, 2021 | The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers c... |
| CVE-2021-24522 | MEDIUM | 6.1 | 1.3% | Aug 9, 2021 | The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before... |
| CVE-2021-24521 | HIGH | 7.2 | 1.6% | Aug 9, 2021 | The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from... |
| CVE-2021-24520 | HIGH | 8.8 | 1.6% | Aug 9, 2021 | The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now