2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46475 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsi_ArraySliceCmd in src/jsiArray.c. This vulnerabilit... |
| CVE-2021-46474 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiEvalCodeSub in src/jsiEval.c. This vulnerability ca... |
| CVE-2021-44994 | MEDIUM | 5.5 | 1.0% | Jan 25, 2022 | There is an Assertion ''JERRY_CONTEXT (jmem_heap_allocated_size) == 0'' failed at /jerry-core/jmem/jmem-heap.c in Jerrys... |
| CVE-2021-44993 | MEDIUM | 5.5 | 0.8% | Jan 25, 2022 | There is an Assertion ''ecma_is_value_boolean (base_value)'' failed at /jerry-core/ecma/operations/ecma-get-put-value.c ... |
| CVE-2021-44992 | MEDIUM | 5.5 | 0.8% | Jan 25, 2022 | There is an Assertion ''ecma_object_is_typedarray (obj_p)'' failed at /jerry-core/ecma/operations/ecma-typedarray-object... |
| CVE-2021-45226 | MEDIUM | 6.5 | 1.4% | Jan 24, 2022 | An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user-controlled HTTP headers, a... |
| CVE-2021-45225 | MEDIUM | 6.1 | 1.1% | Jan 24, 2022 | An issue was discovered in COINS Construction Cloud 11.12. Due to improper input neutralization, it is vulnerable to ref... |
| CVE-2021-45224 | MEDIUM | 6.1 | 1.1% | Jan 24, 2022 | An issue was discovered in COINS Construction Cloud 11.12. In several locations throughout the application, JavaScript c... |
| CVE-2021-45223 | MEDIUM | 6.5 | 1.6% | Jan 24, 2022 | An issue was discovered in COINS Construction Cloud 11.12. Due to insufficient input neutralization, it is vulnerable to... |
| CVE-2021-43589 | MEDIUM | 6.7 | 0.4% | Jan 24, 2022 | Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS)... |
| CVE-2021-36349 | MEDIUM | 4.3 | 0.6% | Jan 24, 2022 | Dell EMC Data Protection Central versions 19.5 and prior contain a Server Side Request Forgery vulnerability in the DPC ... |
| CVE-2021-36343 | MEDIUM | 6.4 | 0.2% | Jan 24, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-36342 | MEDIUM | 6.4 | 0.3% | Jan 24, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2021-42168 | MEDIUM | 6.1 | 0.7% | Jan 24, 2022 | Cross Site Scripting (XSS) in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) by oretnom23, allows attackers... |
| CVE-2021-41930 | MEDIUM | 6.1 | 1.0% | Jan 24, 2022 | Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid Vaccination Scheduler System v1 by oretnom23, al... |
| CVE-2021-41929 | MEDIUM | 6.1 | 1.0% | Jan 24, 2022 | Cross Site Scripting (XSS) in Sourcecodester The Electric Billing Management System 1.0 by oretnom23, allows attackers t... |
| CVE-2021-41658 | MEDIUM | 5.4 | 0.7% | Jan 24, 2022 | Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute ... |
| CVE-2021-25083 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outp... |
| CVE-2021-25080 | MEDIUM | 6.1 | 84.8% | Jan 24, 2022 | The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved v... |
| CVE-2021-25079 | MEDIUM | 6.1 | 6.8% | Jan 24, 2022 | The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id,... |
| CVE-2021-25078 | MEDIUM | 6.1 | 2.3% | Jan 24, 2022 | The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests l... |
| CVE-2021-25074 | MEDIUM | 6.1 | 2.5% | Jan 24, 2022 | The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr... |
| CVE-2021-25062 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outp... |
| CVE-2021-25049 | MEDIUM | 4.8 | 0.7% | Jan 24, 2022 | The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing h... |
| CVE-2021-25035 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error paramete... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now