2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-44965HIGH7.5Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 Th...
CVE-2021-24970HIGH7.2The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using...
CVE-2021-24945HIGH8The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the l...
CVE-2021-24861HIGH7.2The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using i...
CVE-2021-24848HIGH8.8The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authentic...
CVE-2021-24747HIGH7.2The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_a...
CVE-2021-20865HIGH7.5Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au...
CVE-2021-44154HIGH7.2An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_...
CVE-2021-44153HIGH7.2An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable a...
CVE-2021-44151HIGH7.5An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessi...
CVE-2021-40857HIGH8.8Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
CVE-2021-40856HIGH7.5Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
CVE-2021-41805HIGH8.8HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. A...
CVE-2021-41242HIGH8.1OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 1...
CVE-2021-26340HIGH8.4A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to fl...
CVE-2021-27984HIGH8.1In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
CVE-2021-31745HIGH7.5Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access ...
CVE-2021-37935HIGH7.5An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenti...
CVE-2021-29214HIGH7.2A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administr...
CVE-2021-37189HIGH7.5An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sen...
CVE-2021-37188HIGH8.8An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firm...
CVE-2021-43803HIGH7.5Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to ...
CVE-2021-43802HIGH8.8Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file th...
CVE-2021-43982HIGH7.8Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an...
CVE-2021-37861HIGH7.5Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now