2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24342 | MEDIUM | 6.1 | 2.0% | Jun 7, 2021 | The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (w... |
| CVE-2021-24340 | HIGH | 7.5 | 26.9% | Jun 7, 2021 | The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimit... |
| CVE-2021-24337 | HIGH | 8.8 | 1.6% | Jun 7, 2021 | The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is no... |
| CVE-2021-24336 | HIGH | 7.2 | 1.5% | Jun 7, 2021 | The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using ... |
| CVE-2021-28382 | MEDIUM | 5.4 | 1.2% | Jun 7, 2021 | Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious u... |
| CVE-2021-33898 | HIGH | 8.1 | 1.8% | Jun 6, 2021 | In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php ... |
| CVE-2021-33879 | HIGH | 8.1 | 1.0% | Jun 6, 2021 | Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM p... |
| CVE-2021-33881 | MEDIUM | 4.2 | 0.4% | Jun 6, 2021 | On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) o... |
| CVE-2021-33880 | MEDIUM | 5.9 | 2.3% | Jun 6, 2021 | The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic A... |
| CVE-2021-32198 | CRITICAL | 9.8 | 1.2% | Jun 6, 2021 | EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window... |
| CVE-2021-31701 | HIGH | 7.5 | 0.9% | Jun 6, 2021 | Mintty before 3.4.7 mishandles Bracketed Paste Mode. |
| CVE-2021-32641 | MEDIUM | 6.1 | 1.5% | Jun 4, 2021 | auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflecte... |
| CVE-2021-31252 | MEDIUM | 6.1 | 28.6% | Jun 4, 2021 | An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices f... |
| CVE-2021-31251 | CRITICAL | 9.8 | 35.7% | Jun 4, 2021 | An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Tec... |
| CVE-2021-31250 | MEDIUM | 5.4 | 79.6% | Jun 4, 2021 | Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU T... |
| CVE-2021-31249 | MEDIUM | 6.5 | 18.0% | Jun 4, 2021 | A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology I... |
| CVE-2021-26928 | MEDIUM | 6.8 | 1.0% | Jun 4, 2021 | BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products th... |
| CVE-2021-29500 | HIGH | 7.5 | 0.6% | Jun 4, 2021 | bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BU... |
| CVE-2021-30520 | HIGH | 8.8 | 0.9% | Jun 4, 2021 | Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install ... |
| CVE-2021-30519 | HIGH | 8.8 | 0.9% | Jun 4, 2021 | Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a... |
| CVE-2021-30518 | HIGH | 8.8 | 1.3% | Jun 4, 2021 | Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exp... |
| CVE-2021-30517 | HIGH | 8.8 | 2.5% | Jun 4, 2021 | Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2021-30516 | HIGH | 8.8 | 1.3% | Jun 4, 2021 | Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised th... |
| CVE-2021-30515 | HIGH | 8.8 | 1.2% | Jun 4, 2021 | Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-30514 | HIGH | 8.8 | 1.1% | Jun 4, 2021 | Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the ren... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now