2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24425MEDIUM4.8The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin be...
CVE-2021-24371LOW2.7The Import feature of the RSVPMaker WordPress plugin before 8.7.3 (/wp-admin/tools.php?page=rsvpmaker_export_screen) tak...
CVE-2021-3351MEDIUM5.4OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
CVE-2021-34556MEDIUM5.5In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via ...
CVE-2021-35477MEDIUM5.5In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via ...
CVE-2021-32066HIGH7.4An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. Net::IMAP does not raise an e...
CVE-2021-37760CRITICAL9.8A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level ...
CVE-2021-37759CRITICAL9.8A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access l...
CVE-2021-33617MEDIUM5.3Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&use...
CVE-2021-32807HIGH7.2The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. R...
CVE-2021-27495HIGH7.1Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All ...
CVE-2021-27491HIGH7.5Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All ...
CVE-2021-34630MEDIUM6.1In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of al...
CVE-2021-34629MEDIUM4.3The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/...
CVE-2021-22521MEDIUM6.7A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting ve...
CVE-2021-3636MEDIUM4.6It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly...
CVE-2021-35193HIGH7.5Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across di...
CVE-2021-29298MEDIUM5.3Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of ...
CVE-2021-29297MEDIUM5.3Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service an...
CVE-2021-37746MEDIUM6.1textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have suffici...
CVE-2021-37743MEDIUM5.4app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON fo...
CVE-2021-37742MEDIUM5.4app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster re...
CVE-2021-37606MEDIUM5.3Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision ...
CVE-2021-37601HIGH7.5muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, me...
CVE-2021-37600MEDIUM5.5An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now