2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44571Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CV...
CVE-2021-44570Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CV...
CVE-2021-44569Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3200 Reason: This candidate is a duplicate of CV...
CVE-2021-44568MEDIUM6.5Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via ...
CVE-2021-44141MEDIUM4.3All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file...
CVE-2021-27797CRITICAL9.8Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x conta...
CVE-2021-27796MEDIUM6.5A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated att...
CVE-2021-27755MEDIUM5.5"Sametime Android potential path traversal vulnerability when using File class"
CVE-2021-27753MEDIUM5.5"Sametime Android PathTraversal Vulnerability"
CVE-2021-26256MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <=...
CVE-2021-44142HIGH8.8The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SM...
CVE-2021-45008HIGH8.8Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to adm...
CVE-2021-4208HIGH7.2The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using ...
CVE-2021-25101MEDIUM4.8The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST...
CVE-2021-25100MEDIUM6.1The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in t...
CVE-2021-25099MEDIUM6.1The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back i...
CVE-2021-25082HIGH8.8The Popup Builder WordPress plugin before 4.0.7 does not validate and sanitise the sgpb_type parameter before using it i...
CVE-2021-25075LOW3.5The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in ...
CVE-2021-25069HIGH8.8The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using ...
CVE-2021-25060MEDIUM5.4The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its ...
CVE-2021-25058MEDIUM5.4The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within ...
CVE-2021-25057MEDIUM5.4The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XS...
CVE-2021-25055MEDIUM6.1The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" ...
CVE-2021-24921MEDIUM6.1The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before ou...
CVE-2021-24867CRITICAL9.8Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website bei...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now