2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-26628MEDIUM6.1Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges....
CVE-2021-46782MEDIUM6.1The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back...
CVE-2021-46781MEDIUM6.1The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputt...
CVE-2021-46780MEDIUM6.1The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an at...
CVE-2021-25111MEDIUM6.1The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before ...
CVE-2021-24805MEDIUM4.3The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, a...
CVE-2021-24800MEDIUM4.3The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user ...
CVE-2021-45839MEDIUM6.5It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4....
CVE-2021-4212MEDIUM6.7A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook model...
CVE-2021-4211MEDIUM6.7A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, Think...
CVE-2021-4210MEDIUM6.7A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and...
CVE-2021-3972MEDIUM6.7A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS t...
CVE-2021-3971MEDIUM6.7A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices...
CVE-2021-3970MEDIUM6.7A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BI...
CVE-2021-3898MEDIUM6.5Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify ...
CVE-2021-3722MEDIUM5A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow configu...
CVE-2021-3721MEDIUM5.5A denial of service vulnerability was reported in Lenovo PCManager prior to version 4.0.20.10282 that could allow an att...
CVE-2021-38946MEDIUM5.4IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2021-38905MEDIUM4.3IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow an authenticated user to view report pages that they should ...
CVE-2021-38904MEDIUM6.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 could allow a remote attacker to obtain credentials from a user's browse...
CVE-2021-38903MEDIUM5.4IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site scripting, caused by improper validation of ...
CVE-2021-29824MEDIUM4.3IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to priviledge escalation where a lower level user could ha...
CVE-2021-20464MEDIUM6.5IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulnerable to an XML Bomb atta...
CVE-2021-32927MEDIUM6.1An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS T...
CVE-2021-43708MEDIUM5.5The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification l...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now