2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25019MEDIUM6.1The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it b...
CVE-2021-24905HIGH8The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_...
CVE-2021-45117MEDIUM6.5The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointe...
CVE-2021-45878CRITICAL9.1Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the we...
CVE-2021-45877CRITICAL9.8Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /e...
CVE-2021-45876CRITICAL9.8Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of th...
CVE-2021-36100HIGH8.8Specially crafted string in OTRS system configuration can allow the execution of any system command.
CVE-2021-42194HIGH7.2The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the...
CVE-2021-39384CRITICAL9.8DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component /utils/ToHtmlServlet.j...
CVE-2021-39383CRITICAL9.8DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysP...
CVE-2021-44345HIGH7.5Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Inject...
CVE-2021-4031HIGH7.5Syltek application before its 10.22.00 version, does not correctly check that a product ID has a valid payment associate...
CVE-2021-44760MEDIUM5.4Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 vers...
CVE-2021-30771HIGH7.8An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.4, iOS 14.6...
CVE-2021-27789MEDIUM6.5The Web application of Brocade Fabric OS before versions Brocade Fabric OS v9.0.1a and v8.2.3a contains debug statements...
CVE-2021-23209MEDIUM4.8Multiple Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) vulnerabilities discovered in AMP for WP ...
CVE-2021-23150MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in AMP for WP – Accelerated Mobile Pag...
CVE-2021-39046MEDIUM4.9IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 and IBM Business Process Manager 8.5 and 8.6 stores user cre...
CVE-2021-29899MEDIUM6.5IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of ser...
CVE-2021-45835CRITICAL9.8The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of dangerous types to the...
CVE-2021-45834CRITICAL9.8An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via add.php using MIME-bypass...
CVE-2021-22571MEDIUM5.5A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process ...
CVE-2021-45868MEDIUM5.5In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk)....
CVE-2021-45968HIGH7.5An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Pho...
CVE-2021-45967CRITICAL9.8An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend To...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now