2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41810 | MEDIUM | 4.8 | 0.7% | May 2, 2022 | Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Ad... |
| CVE-2021-36844 | MEDIUM | 4.8 | 0.5% | May 2, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on W... |
| CVE-2021-29859 | MEDIUM | 6.8 | 0.3% | May 2, 2022 | IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0... |
| CVE-2021-25102 | MEDIUM | 4.7 | 0.7% | May 2, 2022 | The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect... |
| CVE-2021-25086 | MEDIUM | 6.1 | 1.3% | May 2, 2022 | The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting ... |
| CVE-2021-4200 | MEDIUM | 5.4 | 0.6% | May 2, 2022 | A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restr... |
| CVE-2021-31674 | MEDIUM | 6.1 | 3.8% | May 2, 2022 | Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacke... |
| CVE-2021-31673 | MEDIUM | 6.1 | 3.4% | May 2, 2022 | A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo... |
| CVE-2021-41994 | MEDIUM | 4.8 | 0.2% | Apr 30, 2022 | A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to a... |
| CVE-2021-41993 | MEDIUM | 4.8 | 0.2% | Apr 30, 2022 | A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading ... |
| CVE-2021-41992 | MEDIUM | 5.6 | 0.5% | Apr 30, 2022 | A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading... |
| CVE-2021-3982 | MEDIUM | 5.5 | 0.3% | Apr 29, 2022 | Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with... |
| CVE-2021-41948 | MEDIUM | 5.4 | 0.5% | Apr 29, 2022 | A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List ... |
| CVE-2021-38952 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-43932 | MEDIUM | 6.1 | 0.6% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed up... |
| CVE-2021-43930 | MEDIUM | 4.9 | 1.0% | Apr 28, 2022 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabli... |
| CVE-2021-38939 | MEDIUM | 5.3 | 0.8% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user wi... |
| CVE-2021-38874 | MEDIUM | 4.3 | 0.7% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 allows for users to access information across tenant and domain boundaries in some sit... |
| CVE-2021-34590 | MEDIUM | 5.4 | 0.4% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker coul... |
| CVE-2021-34587 | MEDIUM | 5.3 | 0.9% | Apr 27, 2022 | In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as inpu... |
| CVE-2021-29776 | MEDIUM | 4.3 | 0.6% | Apr 27, 2022 | IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's ... |
| CVE-2021-46423 | MEDIUM | 5.3 | 1.5% | Apr 27, 2022 | Telesquare TLR-2005KSH 1.0.0 is affected by an unauthenticated file download vulnerability that allows a remote attacker... |
| CVE-2021-41041 | MEDIUM | 5.3 | 1.0% | Apr 27, 2022 | In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification w... |
| CVE-2021-36895 | MEDIUM | 6.1 | 0.7% | Apr 26, 2022 | Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG ima... |
| CVE-2021-36867 | MEDIUM | 5.4 | 0.5% | Apr 26, 2022 | Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now