2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29450 | MEDIUM | 4.3 | 2.3% | Apr 15, 2021 | Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo... |
| CVE-2021-21405 | HIGH | 7.5 | 1.0% | Apr 15, 2021 | Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library m... |
| CVE-2021-29447 | MEDIUM | 6.5 | 85.7% | Apr 15, 2021 | Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing iss... |
| CVE-2021-29432 | MEDIUM | 5.7 | 0.9% | Apr 15, 2021 | Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the ... |
| CVE-2021-29431 | MEDIUM | 6.5 | 1.2% | Apr 15, 2021 | Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due t... |
| CVE-2021-29430 | HIGH | 7.5 | 1.8% | Apr 15, 2021 | Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. ... |
| CVE-2021-30245 | HIGH | 8.8 | 4.9% | Apr 15, 2021 | The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The ... |
| CVE-2021-31402 | HIGH | 7.5 | 1.2% | Apr 15, 2021 | The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulner... |
| CVE-2021-28055 | MEDIUM | 6.5 | 0.8% | Apr 15, 2021 | An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, whi... |
| CVE-2021-29433 | MEDIUM | 4.3 | 0.9% | Apr 15, 2021 | Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some param... |
| CVE-2021-26582 | MEDIUM | 6.1 | 0.7% | Apr 15, 2021 | A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0... |
| CVE-2021-3243 | MEDIUM | 6.1 | 0.7% | Apr 15, 2021 | Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet ... |
| CVE-2021-30138 | — | — | — | Apr 15, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-29448 | HIGH | 8.8 | 0.7% | Apr 15, 2021 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the P... |
| CVE-2021-27112 | CRITICAL | 9.8 | 2.4% | Apr 15, 2021 | LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php duri... |
| CVE-2021-31229 | MEDIUM | 6.5 | 1.0% | Apr 15, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handli... |
| CVE-2021-20288 | HIGH | 7.2 | 2.1% | Apr 15, 2021 | An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY... |
| CVE-2021-3487 | — | — | — | Apr 15, 2021 | Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binu... |
| CVE-2021-30209 | MEDIUM | 6.5 | 0.8% | Apr 15, 2021 | Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background witho... |
| CVE-2021-28549 | HIGH | 7.8 | 6.5% | Apr 15, 2021 | Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability whe... |
| CVE-2021-28548 | HIGH | 7.8 | 6.4% | Apr 15, 2021 | Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability whe... |
| CVE-2021-28242 | HIGH | 8.8 | 5.0% | Apr 15, 2021 | SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat... |
| CVE-2021-27673 | MEDIUM | 4.8 | 1.1% | Apr 15, 2021 | Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remot... |
| CVE-2021-27672 | MEDIUM | 4.9 | 1.3% | Apr 15, 2021 | SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers t... |
| CVE-2021-21100 | HIGH | 7.8 | 1.7% | Apr 15, 2021 | Adobe Digital Editions version 4.5.11.187245 (and earlier) is affected by a Privilege Escalation vulnerability during in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now