2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45420CRITICAL9.8Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /...
CVE-2021-45444HIGH7.8In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demon...
CVE-2021-44879MEDIUM5.5In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a mov...
CVE-2021-25115MEDIUM6.4The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log co...
CVE-2021-25110MEDIUM4.3The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user...
CVE-2021-25109LOW2.7The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high ...
CVE-2021-25107MEDIUM6.1The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back...
CVE-2021-25050MEDIUM4.8The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use...
CVE-2021-25033MEDIUM6.1The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the ...
CVE-2021-25018MEDIUM5.4The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_p...
CVE-2021-25014LOW3.5The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings ...
CVE-2021-24904MEDIUM4.8The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the...
CVE-2021-24874MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape t...
CVE-2021-24446MEDIUM5.4The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which...
CVE-2021-4102HIGH8.8Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-4101HIGH8.8Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exp...
CVE-2021-4100HIGH8.8Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit...
CVE-2021-4099HIGH8.8Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit h...
CVE-2021-4098HIGH7.4Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromis...
CVE-2021-46366HIGH8.8An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerabil...
CVE-2021-46365HIGH7.8An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via...
CVE-2021-46364HIGH7.8A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via...
CVE-2021-46363HIGH7.8An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via c...
CVE-2021-46362CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2....
CVE-2021-46361CRITICAL9.8An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and e...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now