2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-42358HIGH8.8The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validati...
CVE-2021-24889HIGH7.2The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which coul...
CVE-2021-24860HIGH7.2The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before u...
CVE-2021-24755HIGH8.8The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL stateme...
CVE-2021-24748HIGH8.8The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET pa...
CVE-2021-38283HIGH7.5Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing se...
CVE-2021-38147HIGH7.5Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as report...
CVE-2021-44094HIGH7.8ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
CVE-2021-41279HIGH8.8BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions use...
CVE-2021-41243HIGH8.8There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS....
CVE-2021-35533HIGH7.5Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-...
CVE-2021-26615HIGH8.8ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW functi...
CVE-2021-36807HIGH8.8An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before versi...
CVE-2021-38686HIGH8.8An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerabil...
CVE-2021-43778HIGH7.5Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the ...
CVE-2021-41268HIGH8.8Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of...
CVE-2021-22957HIGH8.8A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allow...
CVE-2021-38873HIGH7.8IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary command...
CVE-2021-36917HIGH7.5WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie...
CVE-2021-34424HIGH7.5A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before vers...
CVE-2021-21980HIGH7.5The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n...
CVE-2021-43780HIGH8.8Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading da...
CVE-2021-3553HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows...
CVE-2021-3552HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To...
CVE-2021-31822HIGH7.8When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now