2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39753 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In DomainVerificationService, there is a possible way to access app domain verification information due to a missing per... |
| CVE-2021-39751 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permissi... |
| CVE-2021-39748 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent... |
| CVE-2021-39747 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass... |
| CVE-2021-39745 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due... |
| CVE-2021-39744 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due... |
| CVE-2021-39742 | MEDIUM | 5.5 | 0.3% | Mar 30, 2022 | In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could l... |
| CVE-2021-39740 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lea... |
| CVE-2021-41594 | MEDIUM | 6.5 | 0.8% | Mar 30, 2022 | In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by inte... |
| CVE-2021-42970 | MEDIUM | 6.1 | 0.7% | Mar 29, 2022 | Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter. |
| CVE-2021-43701 | MEDIUM | 6.5 | 3.3% | Mar 29, 2022 | CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/articl... |
| CVE-2021-22572 | MEDIUM | 5.5 | 0.1% | Mar 29, 2022 | On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.... |
| CVE-2021-45866 | MEDIUM | 5.4 | 0.5% | Mar 29, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via ... |
| CVE-2021-43105 | MEDIUM | 4.3 | 0.6% | Mar 28, 2022 | A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific maliciou... |
| CVE-2021-43099 | MEDIUM | 4.9 | 1.1% | Mar 28, 2022 | An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.... |
| CVE-2021-4191 | MEDIUM | 5.3 | 80.0% | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv... |
| CVE-2021-39876 | MEDIUM | 4.3 | 0.8% | Mar 28, 2022 | In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of p... |
| CVE-2021-25071 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in a... |
| CVE-2021-25012 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them... |
| CVE-2021-24978 | MEDIUM | 5.3 | 0.5% | Mar 28, 2022 | The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and... |
| CVE-2021-24746 | MEDIUM | 6.1 | 2.2% | Mar 28, 2022 | The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back i... |
| CVE-2021-43721 | MEDIUM | 6.1 | 1.0% | Mar 28, 2022 | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution... |
| CVE-2021-43725 | MEDIUM | 6.1 | 2.6% | Mar 28, 2022 | There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remot... |
| CVE-2021-46434 | MEDIUM | 5.3 | 0.9% | Mar 28, 2022 | EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the appl... |
| CVE-2021-45491 | MEDIUM | 6.5 | 0.8% | Mar 28, 2022 | 3CX System through 2022-03-17 stores cleartext passwords in a database. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now