2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27703MEDIUM5.4Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.
CVE-2021-27702HIGH7.3Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the route...
CVE-2021-27701MEDIUM4.7SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The applic...
CVE-2021-27700HIGH7.6SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner m...
CVE-2021-41737HIGH7.5In Faust 2.23.1, an input file with the lines "// r visualisation tCst" and "//process = +: L: abM-^Q;" and "process = r...
CVE-2021-35473CRITICAL9.1An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e...
CVE-2021-4452MEDIUM5.4The Google Language Translator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple paramet...
CVE-2021-4451HIGH7.2The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and includ...
CVE-2021-4450HIGH8.8The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and includi...
CVE-2021-4449CRITICAL9.8The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '...
CVE-2021-4448CRITICAL9.8The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including...
CVE-2021-4447HIGH8.8The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and inc...
CVE-2021-4446MEDIUM4.3The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and incl...
CVE-2021-4445MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and i...
CVE-2021-4444HIGH7.3The Product Filter by WooBeWoo plugin for WordPress is vulnerable to authorization bypass in versions up to, and includi...
CVE-2021-4443CRITICAL9.8The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, ...
CVE-2021-37577MEDIUM6.8Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetoo...
CVE-2021-38963HIGH8IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the syst...
CVE-2021-38023HIGH8.8Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit he...
CVE-2021-27917MEDIUM5.4Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
CVE-2021-27916HIGH8.1Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletio...
CVE-2021-27915CRITICAL9Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic...
CVE-2021-38133MEDIUM6.5Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al...
CVE-2021-38132CRITICAL9.8Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al...
CVE-2021-38131MEDIUM6.1Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now