2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27953 | HIGH | 7.5 | 1.7% | Aug 3, 2021 | A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Con... |
| CVE-2021-27952 | CRITICAL | 9.8 | 1.1% | Aug 3, 2021 | Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain acces... |
| CVE-2021-36379 | — | — | — | Aug 3, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-36159 | CRITICAL | 9.1 | 2.6% | Aug 3, 2021 | libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and H... |
| CVE-2021-22400 | MEDIUM | 5.5 | 0.4% | Aug 3, 2021 | Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An a... |
| CVE-2021-37833 | MEDIUM | 6.1 | 4.9% | Aug 3, 2021 | A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid applic... |
| CVE-2021-37832 | CRITICAL | 9.8 | 4.1% | Aug 3, 2021 | A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application databa... |
| CVE-2021-35265 | MEDIUM | 6.1 | 3.4% | Aug 3, 2021 | A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attacke... |
| CVE-2021-37916 | MEDIUM | 6.1 | 0.7% | Aug 3, 2021 | Joplin before 2.0.9 allows XSS via button and form in the note body. |
| CVE-2021-37914 | MEDIUM | 6.5 | 1.0% | Aug 3, 2021 | In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input par... |
| CVE-2021-26085 | MEDIUM | 5.3 | 99.9% | Aug 3, 2021 | Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza... |
| CVE-2021-21565 | MEDIUM | 5.3 | 0.9% | Aug 3, 2021 | Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error ... |
| CVE-2021-21563 | MEDIUM | 6.5 | 0.8% | Aug 3, 2021 | Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its ... |
| CVE-2021-21562 | MEDIUM | 4.4 | 0.2% | Aug 3, 2021 | Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PR... |
| CVE-2021-21553 | HIGH | 8.8 | 0.2% | Aug 3, 2021 | Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific condit... |
| CVE-2021-32812 | MEDIUM | 6.1 | 0.8% | Aug 2, 2021 | Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API serv... |
| CVE-2021-32811 | HIGH | 7.2 | 2.3% | Aug 2, 2021 | Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code executio... |
| CVE-2021-32787 | MEDIUM | 4.3 | 0.6% | Aug 2, 2021 | Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leak... |
| CVE-2021-34637 | HIGH | 8.8 | 0.7% | Aug 2, 2021 | The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/... |
| CVE-2021-34635 | MEDIUM | 6.1 | 0.9% | Aug 2, 2021 | The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/... |
| CVE-2021-34632 | HIGH | 8.8 | 0.7% | Aug 2, 2021 | The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ... |
| CVE-2021-34628 | HIGH | 8.8 | 0.7% | Aug 2, 2021 | The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found ... |
| CVE-2021-32019 | MEDIUM | 6.1 | 0.6% | Aug 2, 2021 | There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the l... |
| CVE-2021-29979 | MEDIUM | 6.1 | 0.7% | Aug 2, 2021 | Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in ... |
| CVE-2021-27943 | HIGH | 7.5 | 0.9% | Aug 2, 2021 | The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now