2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24764 | MEDIUM | 6.1 | 0.8% | Feb 1, 2022 | The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[sessio... |
| CVE-2021-24761 | MEDIUM | 6.5 | 0.6% | Feb 1, 2022 | The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not ha... |
| CVE-2021-24707 | MEDIUM | 4.8 | 0.6% | Feb 1, 2022 | The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi... |
| CVE-2021-24686 | MEDIUM | 4.8 | 0.7% | Feb 1, 2022 | The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in... |
| CVE-2021-24648 | MEDIUM | 6.1 | 0.9% | Feb 1, 2022 | The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before ... |
| CVE-2021-46668 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact ... |
| CVE-2021-46667 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. |
| CVE-2021-46666 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE c... |
| CVE-2021-46665 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations. |
| CVE-2021-46664 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr. |
| CVE-2021-46663 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. |
| CVE-2021-46662 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with... |
| CVE-2021-46661 | MEDIUM | 5.5 | 0.4% | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common t... |
| CVE-2021-44114 | MEDIUM | 4.8 | 1.0% | Jan 31, 2022 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows r... |
| CVE-2021-40042 | MEDIUM | 6.5 | 0.6% | Jan 31, 2022 | There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process an... |
| CVE-2021-40033 | MEDIUM | 5.5 | 0.2% | Jan 31, 2022 | There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software... |
| CVE-2021-46659 | MEDIUM | 5.5 | 0.6% | Jan 29, 2022 | MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to ... |
| CVE-2021-46658 | MEDIUM | 5.5 | 0.4% | Jan 29, 2022 | save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_w... |
| CVE-2021-46657 | MEDIUM | 5.5 | 0.4% | Jan 29, 2022 | get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY. |
| CVE-2021-4160 | MEDIUM | 5.9 | 3.8% | Jan 28, 2022 | There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including... |
| CVE-2021-46447 | MEDIUM | 5.4 | 0.5% | Jan 28, 2022 | A cross-site scripting (XSS) vulnerability in H.H.G Multistore v5.1.0 and below allows attackers to execute arbitrary we... |
| CVE-2021-40415 | MEDIUM | 6.5 | 0.8% | Jan 28, 2022 | An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC... |
| CVE-2021-40404 | MEDIUM | 6.5 | 1.2% | Jan 28, 2022 | An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20... |
| CVE-2021-40338 | MEDIUM | 5.3 | 0.7% | Jan 28, 2022 | Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and re... |
| CVE-2021-31567 | MEDIUM | 6.8 | 1.4% | Jan 28, 2022 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now