2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44566 | MEDIUM | 5.4 | 0.7% | Feb 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramF... |
| CVE-2021-44565 | MEDIUM | 5.4 | 0.7% | Feb 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Secur... |
| CVE-2021-43724 | MEDIUM | 4.8 | 0.5% | Feb 24, 2022 | A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the ad... |
| CVE-2021-43943 | MEDIUM | 4.8 | 0.4% | Feb 24, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privile... |
| CVE-2021-26092 | MEDIUM | 6.1 | 1.1% | Feb 24, 2022 | Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 throug... |
| CVE-2021-4115 | MEDIUM | 5.5 | 0.5% | Feb 21, 2022 | There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor ... |
| CVE-2021-44568 | MEDIUM | 6.5 | 1.8% | Feb 21, 2022 | Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via ... |
| CVE-2021-44141 | MEDIUM | 4.3 | 1.1% | Feb 21, 2022 | All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file... |
| CVE-2021-27796 | MEDIUM | 6.5 | 0.9% | Feb 21, 2022 | A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated att... |
| CVE-2021-27755 | MEDIUM | 5.5 | 0.2% | Feb 21, 2022 | "Sametime Android potential path traversal vulnerability when using File class" |
| CVE-2021-27753 | MEDIUM | 5.5 | 0.2% | Feb 21, 2022 | "Sametime Android PathTraversal Vulnerability" |
| CVE-2021-26256 | MEDIUM | 6.1 | 0.8% | Feb 21, 2022 | Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <=... |
| CVE-2021-25101 | MEDIUM | 4.8 | 0.6% | Feb 21, 2022 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST... |
| CVE-2021-25100 | MEDIUM | 6.1 | 0.9% | Feb 21, 2022 | The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in t... |
| CVE-2021-25099 | MEDIUM | 6.1 | 2.1% | Feb 21, 2022 | The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back i... |
| CVE-2021-25060 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its ... |
| CVE-2021-25058 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within ... |
| CVE-2021-25057 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XS... |
| CVE-2021-25055 | MEDIUM | 6.1 | 2.3% | Feb 21, 2022 | The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" ... |
| CVE-2021-24921 | MEDIUM | 6.1 | 0.8% | Feb 21, 2022 | The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before ou... |
| CVE-2021-46701 | MEDIUM | 6.5 | 0.4% | Feb 20, 2022 | PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit... |
| CVE-2021-45081 | MEDIUM | 5.9 | 0.9% | Feb 20, 2022 | An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more se... |
| CVE-2021-45007 | MEDIUM | 6.5 | 0.7% | Feb 20, 2022 | Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on... |
| CVE-2021-46700 | MEDIUM | 6.5 | 0.8% | Feb 19, 2022 | In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double... |
| CVE-2021-40841 | MEDIUM | 6.5 | 1.1% | Feb 18, 2022 | A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the u... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now