2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46422CRITICAL9.8Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute...
CVE-2021-46442CRITICAL9.8In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", a...
CVE-2021-46441HIGH8.8In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" para...
CVE-2021-46421HIGH7.5Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, w...
CVE-2021-46420HIGH7.5Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability,...
CVE-2021-41041MEDIUM5.3In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification w...
CVE-2021-36895MEDIUM6.1Unauthenticated Cross-Site Scripting (XSS) vulnerability in Tripetto's Tripetto plugin <= 5.1.4 on WordPress via SVG ima...
CVE-2021-36867MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19...
CVE-2021-26629HIGH8.8A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the ....
CVE-2021-26628MEDIUM6.1Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges....
CVE-2021-35250HIGH7.5A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to t...
CVE-2021-4225HIGH8.8The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to u...
CVE-2021-46782MEDIUM6.1The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back...
CVE-2021-46781MEDIUM6.1The Coming Soon by Supsystic WordPress plugin before 1.7.6 does not sanitise and escape the tab parameter before outputt...
CVE-2021-46780MEDIUM6.1The Easy Google Maps WordPress plugin before 1.9.32 does not escape the tab parameter before outputting it back in an at...
CVE-2021-39040HIGH8IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or si...
CVE-2021-25111MEDIUM6.1The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before ...
CVE-2021-25094HIGH8.1The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rog...
CVE-2021-24957HIGH8.8The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a S...
CVE-2021-24805MEDIUM4.3The DW Question & Answer Pro WordPress plugin through 1.3.4 does not properly check for CSRF in some of its functions, a...
CVE-2021-24800MEDIUM4.3The DW Question & Answer Pro WordPress plugin through 1.3.4 does not check that the comment to edit belongs to the user ...
CVE-2021-36460HIGH7.8VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authen...
CVE-2021-45842HIGH7.5It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-210714151...
CVE-2021-45841HIGH8.1In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the ta...
CVE-2021-45840CRITICAL9.8It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by send...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now