2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22524MEDIUM4.9Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-23435MEDIUM6.1This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value ...
CVE-2021-40347MEDIUM5.4An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) ca...
CVE-2021-3145MEDIUM6.7In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
CVE-2021-3646MEDIUM6.1btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-38359MEDIUM6.1The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Sit...
CVE-2021-38358MEDIUM6.1The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/...
CVE-2021-38357MEDIUM6.1The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/s...
CVE-2021-38355MEDIUM6.1The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter fo...
CVE-2021-38354MEDIUM6.1The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter ...
CVE-2021-38353MEDIUM6.1The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parame...
CVE-2021-38352MEDIUM6.1The Feedify – Web Push Notifications WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the feedify_ms...
CVE-2021-38351MEDIUM6.1The OSD Subscribe WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the osd_subscribe_message paramet...
CVE-2021-38350MEDIUM6.1The spideranalyse WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the date parameter found in the ~...
CVE-2021-38349MEDIUM6.1The Integration of Moneybird for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the er...
CVE-2021-38348MEDIUM6.1The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpas_id parameter found in t...
CVE-2021-38347MEDIUM6.1The Custom Website Data WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter found in t...
CVE-2021-38341MEDIUM6.1The WooCommerce Payment Gateway Per Category WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a r...
CVE-2021-38340MEDIUM6.1The Wordpress Simple Shop WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the update_row parameter ...
CVE-2021-38339MEDIUM6.1The Simple Matted Thumbnails WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVE...
CVE-2021-38338MEDIUM6.1The Border Loading Bar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `f` and `t` parameter fo...
CVE-2021-38337MEDIUM6.1The RSVPMaker Excel WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SE...
CVE-2021-38336MEDIUM6.1The Edit Comments XT WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_S...
CVE-2021-38335MEDIUM6.1The Wise Agent Capture Forms WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVE...
CVE-2021-38334MEDIUM6.1The WP Design Maps & Places WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the filename parameter ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now