2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-42009MEDIUM4.3An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a speciall...
CVE-2021-25738MEDIUM6.7Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
CVE-2021-32028MEDIUM6.5A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an aut...
CVE-2021-22263MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr...
CVE-2021-20121MEDIUM4The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file rea...
CVE-2021-40541MEDIUM6.1PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descri...
CVE-2021-40191MEDIUM5.4Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all up...
CVE-2021-40542MEDIUM6.1Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja...
CVE-2021-29006MEDIUM6.5rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any ...
CVE-2021-40888MEDIUM5.4Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in...
CVE-2021-40886MEDIUM6.5Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2...
CVE-2021-24737MEDIUM4.8The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow mess...
CVE-2021-24720MEDIUM5.4The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Sc...
CVE-2021-24719MEDIUM6.1The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability...
CVE-2021-24712MEDIUM5.4The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new cal...
CVE-2021-24709MEDIUM4.8The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size...
CVE-2021-24691MEDIUM4.8The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it ...
CVE-2021-24690MEDIUM5.4The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
CVE-2021-24683MEDIUM5.4The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do...
CVE-2021-24681MEDIUM4.8The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before ...
CVE-2021-24656MEDIUM4.8The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp...
CVE-2021-24577MEDIUM5.4The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authen...
CVE-2021-24576MEDIUM5.4The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordio...
CVE-2021-24563MEDIUM6.1The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allow...
CVE-2021-24545MEDIUM5.4The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now