2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20750 | MEDIUM | 6.1 | 1.6% | Jun 28, 2021 | Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p... |
| CVE-2021-20749 | MEDIUM | 5.4 | 1.0% | Jun 28, 2021 | Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.... |
| CVE-2021-20746 | MEDIUM | 5.4 | 1.4% | Jun 28, 2021 | Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker t... |
| CVE-2021-20745 | HIGH | 7.8 | 1.0% | Jun 28, 2021 | Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by load... |
| CVE-2021-20740 | HIGH | 8.8 | 3.1% | Jun 28, 2021 | Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Ga... |
| CVE-2021-35513 | MEDIUM | 6.1 | 1.0% | Jun 27, 2021 | Mermaid before 8.11.0 allows XSS when the antiscript feature is used. |
| CVE-2021-35502 | CRITICAL | 9.8 | 1.1% | Jun 25, 2021 | app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data rel... |
| CVE-2021-25654 | HIGH | 7.8 | 0.8% | Jun 25, 2021 | An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a loca... |
| CVE-2021-1073 | HIGH | 8.3 | 0.9% | Jun 25, 2021 | NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to l... |
| CVE-2021-34427 | CRITICAL | 9.8 | 57.7% | Jun 25, 2021 | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl... |
| CVE-2021-33542 | HIGH | 7 | 1.8% | Jun 25, 2021 | Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution ... |
| CVE-2021-33541 | HIGH | 7.5 | 1.5% | Jun 25, 2021 | Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service ... |
| CVE-2021-33540 | HIGH | 7.3 | 0.7% | Jun 25, 2021 | In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP acc... |
| CVE-2021-33539 | HIGH | 7.2 | 1.1% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in... |
| CVE-2021-33538 | HIGH | 8.8 | 1.0% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists ... |
| CVE-2021-33537 | HIGH | 8.8 | 1.6% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in... |
| CVE-2021-33536 | HIGH | 7.5 | 1.0% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in Ser... |
| CVE-2021-33535 | HIGH | 8.8 | 1.6% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_... |
| CVE-2021-33534 | HIGH | 7.2 | 2.1% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the... |
| CVE-2021-33533 | HIGH | 8.8 | 1.7% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the... |
| CVE-2021-33532 | HIGH | 8.8 | 1.7% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the... |
| CVE-2021-33531 | HIGH | 8.8 | 0.7% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability e... |
| CVE-2021-33530 | HIGH | 8.8 | 1.7% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in enc... |
| CVE-2021-33529 | HIGH | 7.5 | 0.9% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the servic... |
| CVE-2021-33528 | HIGH | 8.8 | 1.1% | Jun 25, 2021 | In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now