2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36341MEDIUM5.5Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated...
CVE-2021-36318MEDIUM6.7Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged...
CVE-2021-36317MEDIUM6.7Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacke...
CVE-2021-45091MEDIUM4.3Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
CVE-2021-45089MEDIUM5.2Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
CVE-2021-24956MEDIUM6.1The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sSh...
CVE-2021-24941MEDIUM6.1The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape th...
CVE-2021-24907MEDIUM6.1The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter befo...
CVE-2021-24738MEDIUM5.4The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which co...
CVE-2021-24578MEDIUM6.1The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting bac...
CVE-2021-43842MEDIUM5.4Wiki.js is a wiki app built on Node.js. Wiki.js versions 2.5.257 and earlier are vulnerable to stored cross-site scripti...
CVE-2021-43847MEDIUM6.5HumHub is an open-source social network kit written in PHP. Prior to HumHub version 1.10.3 or 1.9.3, it could be possibl...
CVE-2021-43846MEDIUM4.3`solidus_frontend` is the cart and storefront for the Solidus e-commerce project. Versions of `solidus_frontend` prior t...
CVE-2021-43750MEDIUM5.5Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthent...
CVE-2021-43749MEDIUM5.5Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthent...
CVE-2021-43748MEDIUM5.5Adobe Premiere Rush versions 1.5.16 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthent...
CVE-2021-43746MEDIUM5.5Adobe Premiere Rush versions 1.5.16 (and earlier) allows access to an uninitialized pointer vulnerability that allows re...
CVE-2021-42808MEDIUM6.7Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
CVE-2021-42138MEDIUM6.5A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted crede...
CVE-2021-36889MEDIUM4.8Multiple Stored Authenticated Cross-Site Scripting (XSS) vulnerabilities were discovered in tarteaucitron.js – Cookies l...
CVE-2021-35248MEDIUM4.3It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate user...
CVE-2021-43441MEDIUM5.3An HTML Injection Vulnerability in iOrder 1.0 allows the remote attacker to execute Malicious HTML codes via the signup ...
CVE-2021-43440MEDIUM6.1Multiple Stored XSS Vulnerabilities in the Source Code of iOrder 1.0 allow remote attackers to execute arbitrary code vi...
CVE-2021-43438MEDIUM5.4Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field
CVE-2021-44916MEDIUM6.1Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now