2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43098HIGH7.2A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
CVE-2021-43097HIGH7.2A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a ma...
CVE-2021-4191MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv...
CVE-2021-39876MEDIUM4.3In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of p...
CVE-2021-25071MEDIUM6.1The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in a...
CVE-2021-25070CRITICAL9.8The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in ...
CVE-2021-25068HIGH7.2The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter wh...
CVE-2021-25064HIGH7.2The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a...
CVE-2021-25012MEDIUM6.1The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them...
CVE-2021-24978MEDIUM5.3The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and...
CVE-2021-24962HIGH8.8The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to ...
CVE-2021-24746MEDIUM6.1The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back i...
CVE-2021-44124HIGH7.5Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input d...
CVE-2021-44103Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42192. Reason: This candidate is a duplicate of ...
CVE-2021-43721MEDIUM6.1Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution...
CVE-2021-43725MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remot...
CVE-2021-46434MEDIUM5.3EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the appl...
CVE-2021-46433CRITICAL10In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox t...
CVE-2021-45491MEDIUM6.53CX System through 2022-03-17 stores cleartext passwords in a database.
CVE-2021-45490CRITICAL9.1The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 l...
CVE-2021-44617CRITICAL9.8A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest....
CVE-2021-44213MEDIUM6.1OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
CVE-2021-44212MEDIUM6.1OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
CVE-2021-44211MEDIUM5.4OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
CVE-2021-44210MEDIUM6.1OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now