2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37209MEDIUM6.7A vulnerability has been identified in RUGGEDCOM i800 (All versions < V4.3.8), RUGGEDCOM i801 (All versions < V4.3.8), R...
CVE-2021-37208CRITICAL9.6A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80...
CVE-2021-43944HIGH7.2This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has ...
CVE-2021-36809MEDIUM6A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potent...
CVE-2021-38989MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2021-38988MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2021-4199HIGH7.8Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used...
CVE-2021-4198MEDIUM6.1A NULL Pointer Dereference vulnerability in the messaging_ipc.dll component as used in Bitdefender Total Security, Inter...
CVE-2021-25098MEDIUM6.5The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, al...
CVE-2021-25087HIGH7.5The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo...
CVE-2021-25039MEDIUM6.1The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_conte...
CVE-2021-25038MEDIUM6.1The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog...
CVE-2021-25009MEDIUM5.3The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensiti...
CVE-2021-24961MEDIUM5.4The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does ...
CVE-2021-24960MEDIUM5.4The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allow...
CVE-2021-24953MEDIUM6.1The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputti...
CVE-2021-24952HIGH8.8The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet...
CVE-2021-24826MEDIUM5.4The Custom Content Shortcode WordPress plugin before 4.0.2 does not escape custom fields before outputting them, which c...
CVE-2021-24825MEDIUM4.3The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to its load shortcode, whic...
CVE-2021-24824MEDIUM4.3The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated use...
CVE-2021-24821MEDIUM5.4The Cost Calculator WordPress plugin before 1.6 allows users with a role as low as Contributor to perform Stored Cross-S...
CVE-2021-24810MEDIUM4.8The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting th...
CVE-2021-24778HIGH7.2The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or ...
CVE-2021-24777HIGH7.2The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the s...
CVE-2021-24216HIGH7.2The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows admin...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now