2021 CVE Vulnerabilities

23,464 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24447MEDIUM5.3The WP Image Zoom WordPress plugin before 1.47 did not validate its tab parameter before using it in the include_once() ...
CVE-2021-24436MEDIUM6.1The W3 Total Cache WordPress plugin before 2.1.4 was vulnerable to a reflected Cross-Site Scripting (XSS) security vulne...
CVE-2021-33592CRITICAL9.8NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Specia...
CVE-2021-36773HIGH7.5uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking...
CVE-2021-36772MEDIUM6.1Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
CVE-2021-36771MEDIUM6.1Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
CVE-2021-33911CRITICAL9.8Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
CVE-2021-36213HIGH7.5HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware inten...
CVE-2021-32574HIGH7.5HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination ...
CVE-2021-36769MEDIUM5.3A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop befo...
CVE-2021-3614MEDIUM6.8A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevat...
CVE-2021-3550HIGH7.8A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privil...
CVE-2021-3453MEDIUM4.6Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could ...
CVE-2021-3452MEDIUM6.7A potential vulnerability in the system shutdown SMI callback function in some ThinkPad models may allow an attacker wit...
CVE-2021-34481HIGH8.8A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file ...
CVE-2021-34467HIGH7.1Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-34466MEDIUM5.7Windows Hello Security Feature Bypass Vulnerability
CVE-2021-34464HIGH7.8Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-34462HIGH7Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
CVE-2021-34461HIGH7.8Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2021-34460HIGH7.8Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-34459HIGH7.8Windows AppContainer Elevation Of Privilege Vulnerability
CVE-2021-34458CRITICAL9.9Windows Kernel Remote Code Execution Vulnerability
CVE-2021-34457MEDIUM5.5Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2021-34456HIGH7.8Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now