2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-40823MEDIUM5.9A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a ...
CVE-2021-33366MEDIUM5.5Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafte...
CVE-2021-33364MEDIUM5.5Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted fil...
CVE-2021-24725MEDIUM4.3The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete co...
CVE-2021-24724MEDIUM5.4The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, w...
CVE-2021-24623MEDIUM4.8The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape ...
CVE-2021-24621MEDIUM4.8The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be ...
CVE-2021-24619MEDIUM4.8The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing maliciou...
CVE-2021-24614MEDIUM4.8The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it...
CVE-2021-24605MEDIUM5.4The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenti...
CVE-2021-24586MEDIUM4.3The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could a...
CVE-2021-24560MEDIUM6.1The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before ...
CVE-2021-24523MEDIUM5.4The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputt...
CVE-2021-24510MEDIUM6.1The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back...
CVE-2021-24508MEDIUM6.1The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter ...
CVE-2021-24490MEDIUM6.8The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import...
CVE-2021-24431MEDIUM4.3The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did n...
CVE-2021-32135MEDIUM5.5The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ...
CVE-2021-32132MEDIUM5.5The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ...
CVE-2021-29643MEDIUM5.4PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a co...
CVE-2021-32137MEDIUM5.5Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of s...
CVE-2021-32134MEDIUM5.5The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via...
CVE-2021-40214MEDIUM5.4Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
CVE-2021-22528MEDIUM5.4Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-22526MEDIUM6.1Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now