2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36828 | MEDIUM | 4.8 | 0.5% | Apr 15, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions. |
| CVE-2021-40425 | MEDIUM | 6.5 | 0.3% | Apr 14, 2022 | An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A sp... |
| CVE-2021-40424 | MEDIUM | 6.5 | 0.3% | Apr 14, 2022 | An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A sp... |
| CVE-2021-40405 | MEDIUM | 6.5 | 1.1% | Apr 14, 2022 | A denial of service vulnerability exists in the cgiserver.cgi Upgrade API functionality of Reolink RLC-410W v3.0.0.136_2... |
| CVE-2021-21967 | MEDIUM | 5.9 | 0.7% | Apr 14, 2022 | An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 37... |
| CVE-2021-45228 | MEDIUM | 5.4 | 0.6% | Apr 14, 2022 | An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the d... |
| CVE-2021-45227 | MEDIUM | 5.4 | 0.6% | Apr 14, 2022 | An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file... |
| CVE-2021-43633 | MEDIUM | 5.4 | 0.5% | Apr 14, 2022 | Sourcecodester Messaging Web Application 1.0 is vulnerable to stored XSS. If a sender inserts valid scripts into the cha... |
| CVE-2021-43288 | MEDIUM | 5.4 | 0.9% | Apr 14, 2022 | An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious J... |
| CVE-2021-43154 | MEDIUM | 6.1 | 0.5% | Apr 13, 2022 | Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action i... |
| CVE-2021-43742 | MEDIUM | 5.4 | 0.5% | Apr 13, 2022 | CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature. |
| CVE-2021-28544 | MEDIUM | 4.3 | 2.7% | Apr 12, 2022 | Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should b... |
| CVE-2021-41005 | MEDIUM | 6.5 | 0.8% | Apr 12, 2022 | A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0. |
| CVE-2021-39814 | MEDIUM | 6.7 | 0.1% | Apr 12, 2022 | In ppmp_validate_wsm of drm_fw.c, there is a possible out of bounds write due to an incorrect bounds check. This could l... |
| CVE-2021-39805 | MEDIUM | 6.5 | 0.3% | Apr 12, 2022 | In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing bounds check. This coul... |
| CVE-2021-39804 | MEDIUM | 6.5 | 0.4% | Apr 12, 2022 | In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persi... |
| CVE-2021-39803 | MEDIUM | 6.5 | 0.6% | Apr 12, 2022 | In ~Impl of C2AllocatorIon.cpp, there is a possible out of bounds read due to a use after free. This could lead to remot... |
| CVE-2021-39800 | MEDIUM | 5.5 | 0.1% | Apr 12, 2022 | In ion_ioctl of ion-ioctl.c, there is a possible way to leak kernel head data due to a use after free. This could lead t... |
| CVE-2021-36914 | MEDIUM | 6.1 | 0.5% | Apr 12, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to Reflected Cross-Site Scripting (XSS) in CalderaWP License Man... |
| CVE-2021-43177 | MEDIUM | 5.3 | 0.8% | Apr 11, 2022 | As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to re... |
| CVE-2021-36910 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20. |
| CVE-2021-36896 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress p... |
| CVE-2021-36893 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress... |
| CVE-2021-36848 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versio... |
| CVE-2021-36846 | MEDIUM | 4.8 | 0.6% | Apr 11, 2022 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now