2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-32287HIGH7.8An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfiguration...
CVE-2021-32286HIGH7.8An issue was discovered in hcxtools through 6.1.6. A global-buffer-overflow exists in the function pcapngoptionwalk loca...
CVE-2021-32284HIGH7.8An issue was discovered in gravity through 0.8.1. A NULL pointer dereference exists in the function ircode_register_pop_...
CVE-2021-32281HIGH7.8An issue was discovered in gravity through 0.8.1. A heap-buffer-overflow exists in the function gnode_function_add_upval...
CVE-2021-32278HIGH7.8An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function lt_prediction located in ...
CVE-2021-32277HIGH7.8An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_analysis_32 locat...
CVE-2021-32274HIGH7.8An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 loca...
CVE-2021-32273HIGH7.8An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4rea...
CVE-2021-32272HIGH7.8An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read....
CVE-2021-32271HIGH7.8An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located...
CVE-2021-32268HIGH7.8Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbit...
CVE-2021-32265HIGH8.8An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStre...
CVE-2021-39402HIGH7.2MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is...
CVE-2021-24663HIGH7.2The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that ...
CVE-2021-24639HIGH8.1The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_...
CVE-2021-24636HIGH8.1The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make log...
CVE-2021-24606HIGH8.8The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before...
CVE-2021-24511HIGH7.2The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_...
CVE-2021-24404HIGH8.8The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised...
CVE-2021-24403HIGH7.2The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitis...
CVE-2021-24402HIGH7.2The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not san...
CVE-2021-24401HIGH7.2The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is ...
CVE-2021-24400HIGH7.2The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanit...
CVE-2021-24399HIGH7.2The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, ...
CVE-2021-24398HIGH7.2The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is n...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now