2021 CVE Vulnerabilities
23,464 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29780 | MEDIUM | 4.7 | 0.7% | Jul 19, 2021 | IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should no... |
| CVE-2021-29707 | HIGH | 7.8 | 0.3% | Jul 19, 2021 | IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to... |
| CVE-2021-20507 | MEDIUM | 5.4 | 0.5% | Jul 19, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-35449 | HIGH | 7.8 | 1.4% | Jul 19, 2021 | The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,... |
| CVE-2021-35043 | MEDIUM | 6.1 | 1.5% | Jul 19, 2021 | OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected)... |
| CVE-2021-20110 | CRITICAL | 9.8 | 7.4% | Jul 19, 2021 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can stati... |
| CVE-2021-20109 | HIGH | 7.5 | 1.4% | Jul 19, 2021 | Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure t... |
| CVE-2021-20108 | HIGH | 7.5 | 3.0% | Jul 19, 2021 | Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Serve... |
| CVE-2021-34817 | MEDIUM | 6.1 | 1.3% | Jul 19, 2021 | A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary ... |
| CVE-2021-32014 | MEDIUM | 5.5 | 0.9% | Jul 19, 2021 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xl... |
| CVE-2021-32013 | MEDIUM | 5.5 | 0.9% | Jul 19, 2021 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ... |
| CVE-2021-32012 | MEDIUM | 5.5 | 0.9% | Jul 19, 2021 | SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ... |
| CVE-2021-3279 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | sz.chat version 4 allows injection of web scripts and HTML in the message box. |
| CVE-2021-31216 | HIGH | 8.1 | 0.7% | Jul 19, 2021 | Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (... |
| CVE-2021-35968 | MEDIUM | 4.3 | 1.0% | Jul 19, 2021 | The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly.... |
| CVE-2021-35967 | MEDIUM | 5.3 | 1.3% | Jul 19, 2021 | The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attack... |
| CVE-2021-35966 | MEDIUM | 6.1 | 0.8% | Jul 19, 2021 | The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing... |
| CVE-2021-35965 | CRITICAL | 9.8 | 2.4% | Jul 19, 2021 | The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the so... |
| CVE-2021-35964 | CRITICAL | 9.8 | 1.1% | Jul 19, 2021 | The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remot... |
| CVE-2021-35963 | CRITICAL | 9.8 | 2.4% | Jul 19, 2021 | The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which a... |
| CVE-2021-33501 | CRITICAL | 9.6 | 7.9% | Jul 19, 2021 | Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL. |
| CVE-2021-33027 | CRITICAL | 9.8 | 1.3% | Jul 19, 2021 | Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce. |
| CVE-2021-24482 | MEDIUM | 4.8 | 0.7% | Jul 19, 2021 | The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high ... |
| CVE-2021-24453 | HIGH | 8.8 | 5.0% | Jul 19, 2021 | The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to ... |
| CVE-2021-24452 | MEDIUM | 6.1 | 2.0% | Jul 19, 2021 | The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now