2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25090MEDIUM5.4The Portfolio Gallery, Product Catalog WordPress plugin before 2.1.0 does not have authorisation and CSRF checks in vari...
CVE-2021-24987MEDIUM6.1The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape t...
CVE-2021-24986MEDIUM6.1The Post Grid WordPress plugin before 2.1.16 does not escape the keyword parameter before outputting it back in an attri...
CVE-2021-32162HIGH8.8A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
CVE-2021-32161MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the File Manager feature.
CVE-2021-32160MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.
CVE-2021-32159HIGH8.8A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
CVE-2021-32158MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
CVE-2021-32157CRITICAL9.6A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-32156HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
CVE-2021-43149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-43009MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the reque...
CVE-2021-36293MEDIUM6.7Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin...
CVE-2021-36290MEDIUM6.7Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin...
CVE-2021-36288CRITICAL9.1Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated...
CVE-2021-36287CRITICAL9.8Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which ...
CVE-2021-43498HIGH7.5An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden,...
CVE-2021-43503Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-43517CRITICAL9.8FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port whe...
CVE-2021-43515HIGH7.8CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the...
CVE-2021-43521HIGH7.5A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.
CVE-2021-43483HIGH8An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a mal...
CVE-2021-40656HIGH8.8libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
CVE-2021-41715HIGH8.8libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
CVE-2021-46367HIGH7.2RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now