2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36891MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery by Supsystic plugin <= 1.15.5 at WordPress allows chang...
CVE-2021-25261HIGH7.8Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker...
CVE-2021-43756HIGH7.8Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthe...
CVE-2021-43754HIGH7.8Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling ...
CVE-2021-40776MEDIUM6.1Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom...
CVE-2021-42732HIGH7.8Access of Memory Location After End of Buffer (CWE-788)
CVE-2021-40940CRITICAL9.8Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.
CVE-2021-40727HIGH7.8Access of Memory Location After End of Buffer (CWE-788
CVE-2021-39820HIGH7.8Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability...
CVE-2021-41672MEDIUM6.5PEEL Shopping CMS 9.4.0 is vulnerable to authenticated SQL injection in utilisateurs.php. A user that belongs to the adm...
CVE-2021-40910MEDIUM6.1There is a reflective cross-site scripting (XSS) vulnerability in the PHPCMS V9.6.3 management side.
CVE-2021-33036HIGH8.8In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to ...
CVE-2021-39806HIGH7.8In closef of label_backends_android.c, there is a possible way to corrupt memory due to a double free. This could lead t...
CVE-2021-36901MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in Phil Baker's Age Gate plugin <= 2.17.0 at WordPress.
CVE-2021-39691HIGH7.3In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This...
CVE-2021-41413HIGH7.8ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_conve...
CVE-2021-40212CRITICAL9.8An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, informa...
CVE-2021-42675CRITICAL9.8Kreado Kreasfero 1.5 does not properly sanitize uploaded files to the media directory. One can upload a malicious PHP fi...
CVE-2021-40660HIGH7.5An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launc...
CVE-2021-40678MEDIUM5.4In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=bat...
CVE-2021-40658MEDIUM4.8Textpattern 4.8.7 is affected by a HTML injection vulnerability through “Content>Write>Body”.
CVE-2021-40633HIGH8.8A memory leak (out-of-memory) in gif2rgb in util/gif2rgb.c in giflib 5.1.4 allows remote attackers trigger an out of mem...
CVE-2021-40650MEDIUM6.5In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
CVE-2021-40649MEDIUM6.5In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
CVE-2021-40616MEDIUM6.5thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account wit...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now