2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26628 | MEDIUM | 6.1 | 0.7% | Apr 26, 2022 | Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges.... |
| CVE-2021-46782 | MEDIUM | 6.1 | 0.8% | Apr 25, 2022 | The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back... |
| CVE-2021-46781 | MEDIUM | 6.1 | 0.8% | Apr 25, 2022 | The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputt... |
| CVE-2021-46780 | MEDIUM | 6.1 | 0.8% | Apr 25, 2022 | The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an at... |
| CVE-2021-25111 | MEDIUM | 6.1 | 1.9% | Apr 25, 2022 | The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before ... |
| CVE-2021-24805 | MEDIUM | 4.3 | 0.4% | Apr 25, 2022 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, a... |
| CVE-2021-24800 | MEDIUM | 4.3 | 0.6% | Apr 25, 2022 | The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user ... |
| CVE-2021-45839 | MEDIUM | 6.5 | 9.4% | Apr 25, 2022 | It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.... |
| CVE-2021-4212 | MEDIUM | 6.7 | 0.2% | Apr 22, 2022 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook model... |
| CVE-2021-4211 | MEDIUM | 6.7 | 0.2% | Apr 22, 2022 | A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, Think... |
| CVE-2021-4210 | MEDIUM | 6.7 | 0.2% | Apr 22, 2022 | A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and... |
| CVE-2021-3972 | MEDIUM | 6.7 | 3.0% | Apr 22, 2022 | A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS t... |
| CVE-2021-3971 | MEDIUM | 6.7 | 1.3% | Apr 22, 2022 | A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices... |
| CVE-2021-3970 | MEDIUM | 6.7 | 1.3% | Apr 22, 2022 | A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BI... |
| CVE-2021-3898 | MEDIUM | 6.5 | 0.4% | Apr 22, 2022 | Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify ... |
| CVE-2021-3722 | MEDIUM | 5 | 0.2% | Apr 22, 2022 | A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configu... |
| CVE-2021-3721 | MEDIUM | 5.5 | 0.2% | Apr 22, 2022 | A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an att... |
| CVE-2021-38946 | MEDIUM | 5.4 | 0.6% | Apr 22, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2021-38905 | MEDIUM | 4.3 | 0.9% | Apr 22, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should ... |
| CVE-2021-38904 | MEDIUM | 6.5 | 1.7% | Apr 22, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browse... |
| CVE-2021-38903 | MEDIUM | 5.4 | 0.9% | Apr 22, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of ... |
| CVE-2021-29824 | MEDIUM | 4.3 | 0.8% | Apr 22, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could ha... |
| CVE-2021-20464 | MEDIUM | 6.5 | 1.3% | Apr 22, 2022 | IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb atta... |
| CVE-2021-32927 | MEDIUM | 6.1 | 0.6% | Apr 22, 2022 | An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS T... |
| CVE-2021-43708 | MEDIUM | 5.5 | 0.3% | Apr 21, 2022 | The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification l... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now