2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-33087MEDIUM5.5Improper authentication in the installer for the Intel(R) NUC M15 Laptop Kit Management Engine driver pack before versio...
CVE-2021-33086MEDIUM5.5Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of s...
CVE-2021-42360MEDIUM5.4On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab...
CVE-2021-33480MEDIUM5.5An use-after-free vulnerability was discovered in gocr through 0.53-20200802 in context_correction() in pgm2asc.c.
CVE-2021-43977MEDIUM6.1SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS.
CVE-2021-43976MEDIUM4.6In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (w...
CVE-2021-43975MEDIUM6.7In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_uti...
CVE-2021-42250MEDIUM6.5Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to f...
CVE-2021-38959MEDIUM5.5IBM SPSS Statistics for Windows 24.0, 25.0, 26.0, 27.0, 27.0.1, and 28.0 could allow a local user to cause a denial of s...
CVE-2021-29861MEDIUM6.2IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in EFS to expose sensi...
CVE-2021-29860MEDIUM6.2IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the libc.a library ...
CVE-2021-24856MEDIUM4.8The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c...
CVE-2021-24854MEDIUM5.4The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could...
CVE-2021-24853MEDIUM4.3The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector se...
CVE-2021-24852MEDIUM6.5The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which c...
CVE-2021-24851MEDIUM4.3The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta...
CVE-2021-24850MEDIUM5.4The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. ...
CVE-2021-24841MEDIUM4.8The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2021-24834MEDIUM5.4The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in th...
CVE-2021-24833MEDIUM5.4The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in t...
CVE-2021-24815MEDIUM4.8The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But...
CVE-2021-24802MEDIUM6.5The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make...
CVE-2021-24796MEDIUM6.1The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets be...
CVE-2021-24787MEDIUM4.8The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings...
CVE-2021-24776MEDIUM4.3The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which co...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now