2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-31885HIGH7.5A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All ver...
CVE-2021-31883HIGH7.5A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-31882HIGH7.5A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-31881HIGH7.5A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-41253HIGH8.1Zydis is an x86/x86-64 disassembler library. Users of Zydis versions v3.2.0 and older that use the string functions prov...
CVE-2021-24844HIGH7.2The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL s...
CVE-2021-24835HIGH8.8The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before...
CVE-2021-24829HIGH8.8The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to t...
CVE-2021-24791HIGH7.2The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" req...
CVE-2021-24695HIGH7.5The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any au...
CVE-2021-24669HIGH8.8The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter...
CVE-2021-24647HIGH8.1The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres...
CVE-2021-24631HIGH8.8The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in...
CVE-2021-24630HIGH8.8The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQ...
CVE-2021-24629HIGH7.2The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before usi...
CVE-2021-24628HIGH7.2The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL ...
CVE-2021-24627HIGH7.2The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in...
CVE-2021-24626HIGH8.8The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allow...
CVE-2021-24625HIGH7.2The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from...
CVE-2021-24575HIGH8.8The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared s...
CVE-2021-24537HIGH7.2The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened...
CVE-2021-39182HIGH7.5EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorith...
CVE-2021-28022HIGH7.5Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate inform...
CVE-2021-41772HIGH7.5Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing ...
CVE-2021-41771HIGH7.5ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Loc...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now