2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28190 | MEDIUM | 4.9 | 1.2% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Generate new certificate function) does not verify the... |
| CVE-2021-28189 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by ... |
| CVE-2021-28188 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify th... |
| CVE-2021-28187 | MEDIUM | 4.9 | 1.2% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Generate new SSL certificate) does not verify the stri... |
| CVE-2021-28186 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify t... |
| CVE-2021-28185 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify t... |
| CVE-2021-28184 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The Active Directory configuration function in ASUS BMC’s firmware Web management page does not verify the string length... |
| CVE-2021-28183 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Web License configuration setting) does not verify the... |
| CVE-2021-28182 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length ente... |
| CVE-2021-28181 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Remote video configuration setting) does not verify th... |
| CVE-2021-28180 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Audit log configuration setting) does not verify the s... |
| CVE-2021-28179 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Media support configuration setting) does not verify t... |
| CVE-2021-28178 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The UEFI configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by ... |
| CVE-2021-28177 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The LDAP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by ... |
| CVE-2021-28176 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The DNS configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by u... |
| CVE-2021-28175 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The Radius configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered b... |
| CVE-2021-30141 | HIGH | 7.5 | 1.5% | Apr 5, 2021 | Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as... |
| CVE-2021-20308 | CRITICAL | 9.8 | 2.5% | Apr 5, 2021 | Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of se... |
| CVE-2021-20307 | CRITICAL | 9.8 | 1.9% | Apr 5, 2021 | Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read a... |
| CVE-2021-20305 | HIGH | 8.1 | 1.6% | Apr 5, 2021 | A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, ED... |
| CVE-2021-24212 | CRITICAL | 9.8 | 7.9% | Apr 5, 2021 | The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allo... |
| CVE-2021-24211 | MEDIUM | 5.4 | 0.6% | Apr 5, 2021 | The WordPress Related Posts plugin through 3.6.4 contains an authenticated (admin+) stored XSS vulnerability in the titl... |
| CVE-2021-24210 | MEDIUM | 6.1 | 3.1% | Apr 5, 2021 | There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request t... |
| CVE-2021-24209 | HIGH | 7.2 | 23.8% | Apr 5, 2021 | The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due ... |
| CVE-2021-24208 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML,... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now