2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37840 | HIGH | 8.8 | 1.7% | Aug 2, 2021 | aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a... |
| CVE-2021-37167 | CRITICAL | 9.8 | 1.7% | Aug 2, 2021 | An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by releas... |
| CVE-2021-37166 | HIGH | 7.5 | 1.8% | Aug 2, 2021 | A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus P... |
| CVE-2021-37164 | CRITICAL | 9.8 | 3.4% | Aug 2, 2021 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released ver... |
| CVE-2021-37163 | CRITICAL | 9.8 | 1.4% | Aug 2, 2021 | An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released ver... |
| CVE-2021-37162 | CRITICAL | 9.8 | 3.3% | Aug 2, 2021 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released ver... |
| CVE-2021-37161 | CRITICAL | 9.8 | 3.3% | Aug 2, 2021 | A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, o... |
| CVE-2021-37160 | CRITICAL | 9.8 | 8.2% | Aug 2, 2021 | A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released... |
| CVE-2021-20332 | MEDIUM | 4.4 | 0.3% | Aug 2, 2021 | Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in... |
| CVE-2021-37216 | MEDIUM | 6.1 | 3.2% | Aug 2, 2021 | QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript w... |
| CVE-2021-37165 | CRITICAL | 9.8 | 3.3% | Aug 2, 2021 | A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released ver... |
| CVE-2021-34575 | HIGH | 7.5 | 1.0% | Aug 2, 2021 | In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by ... |
| CVE-2021-34574 | MEDIUM | 4.3 | 0.7% | Aug 2, 2021 | In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 a... |
| CVE-2021-33527 | CRITICAL | 9.8 | 4.5% | Aug 2, 2021 | In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the se... |
| CVE-2021-33526 | HIGH | 7.8 | 0.3% | Aug 2, 2021 | In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service runnin... |
| CVE-2021-24504 | MEDIUM | 6.1 | 0.8% | Aug 2, 2021 | The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Fi... |
| CVE-2021-24503 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode... |
| CVE-2021-24498 | MEDIUM | 6.1 | 3.1% | Aug 2, 2021 | The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET param... |
| CVE-2021-24496 | MEDIUM | 6.1 | 0.8% | Aug 2, 2021 | The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and success... |
| CVE-2021-24492 | HIGH | 8.8 | 1.6% | Aug 2, 2021 | The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, avai... |
| CVE-2021-24488 | MEDIUM | 6.1 | 11.3% | Aug 2, 2021 | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not prope... |
| CVE-2021-24484 | HIGH | 7.2 | 1.3% | Aug 2, 2021 | The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did n... |
| CVE-2021-24483 | HIGH | 7.2 | 1.4% | Aug 2, 2021 | The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did n... |
| CVE-2021-24481 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an a... |
| CVE-2021-24480 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now