2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32859 | MEDIUM | 6.1 | 0.5% | Feb 21, 2023 | The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender v... |
| CVE-2021-32858 | MEDIUM | 6.1 | 0.6% | Feb 21, 2023 | esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-ht... |
| CVE-2021-32857 | MEDIUM | 6.1 | 0.7% | Feb 21, 2023 | Cockpit is a content management system that allows addition of content management functionality to any site. In versions... |
| CVE-2021-32856 | MEDIUM | 6.1 | 0.6% | Feb 21, 2023 | Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to... |
| CVE-2021-32855 | MEDIUM | 6.1 | 0.6% | Feb 21, 2023 | Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS... |
| CVE-2021-32854 | MEDIUM | 6.1 | 0.5% | Feb 21, 2023 | textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting ... |
| CVE-2021-32853 | CRITICAL | 9.6 | 3.1% | Feb 20, 2023 | Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.2... |
| CVE-2021-32852 | CRITICAL | 9 | 0.9% | Feb 20, 2023 | Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edi... |
| CVE-2021-32851 | MEDIUM | 6.1 | 0.7% | Feb 20, 2023 | Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting ... |
| CVE-2021-32850 | MEDIUM | 6.1 | 0.8% | Feb 20, 2023 | jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site sc... |
| CVE-2021-32848 | HIGH | 7.5 | 1.0% | Feb 20, 2023 | Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide... |
| CVE-2021-32847 | MEDIUM | 6.5 | 0.4% | Feb 20, 2023 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malic... |
| CVE-2021-32846 | HIGH | 7.8 | 0.3% | Feb 17, 2023 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vts... |
| CVE-2021-32845 | HIGH | 7.8 | 0.3% | Feb 17, 2023 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper... |
| CVE-2021-32844 | MEDIUM | 5.5 | 0.2% | Feb 17, 2023 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper... |
| CVE-2021-32843 | MEDIUM | 5.5 | 0.2% | Feb 17, 2023 | HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper... |
| CVE-2021-26277 | CRITICAL | 9.8 | 0.3% | Feb 17, 2023 | The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to per... |
| CVE-2021-3172 | HIGH | 8.1 | 0.6% | Feb 17, 2023 | An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Servic... |
| CVE-2021-35261 | CRITICAL | 9.8 | 0.8% | Feb 17, 2023 | File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker t... |
| CVE-2021-34182 | CRITICAL | 9.8 | 0.9% | Feb 17, 2023 | An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions. |
| CVE-2021-34164 | HIGH | 8.8 | 0.8% | Feb 17, 2023 | Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set p... |
| CVE-2021-33983 | HIGH | 7.8 | 0.3% | Feb 17, 2023 | Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc... |
| CVE-2021-33950 | HIGH | 7.5 | 0.7% | Feb 17, 2023 | An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function... |
| CVE-2021-33949 | CRITICAL | 9.8 | 1.0% | Feb 17, 2023 | An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function... |
| CVE-2021-33948 | CRITICAL | 9.8 | 0.8% | Feb 17, 2023 | SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the usernam... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now