2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25041MEDIUM6.1The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues v...
CVE-2021-24939MEDIUM6.1The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login...
CVE-2021-24938MEDIUM6.1The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_da...
CVE-2021-24935MEDIUM6.1The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family pa...
CVE-2021-24930MEDIUM5.4The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name fi...
CVE-2021-24924MEDIUM6.1The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in...
CVE-2021-24759MEDIUM5.4The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, wh...
CVE-2021-24718MEDIUM4.8The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett...
CVE-2021-24714MEDIUM4.8The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier...
CVE-2021-43043MEDIUM6.5An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files s...
CVE-2021-43039MEDIUM6.5An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anony...
CVE-2021-4005MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-35415MEDIUM4.8A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte...
CVE-2021-38909MEDIUM5.4IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-29867MEDIUM5.4IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should ...
CVE-2021-29719MEDIUM5.3IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifyin...
CVE-2021-29716MEDIUM6.5IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user shou...
CVE-2021-20493MEDIUM6.1IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-43991MEDIUM5.4The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability ...
CVE-2021-43673MEDIUM6.1dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of th...
CVE-2021-4000MEDIUM6.1showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-44022MEDIUM5.5A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected ins...
CVE-2021-43772MEDIUM5.5Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be ...
CVE-2021-25785MEDIUM4.8Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management colum...
CVE-2021-43327MEDIUM4.6An issue was discovered on Renesas RX65 and RX65N devices. With a VCC glitch, an attacker can extract the security ID ke...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now