2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-40528MEDIUM5.9The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two c...
CVE-2021-36096MEDIUM4.9Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O...
CVE-2021-36095MEDIUM5.3Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS ...
CVE-2021-36094MEDIUM5.4It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OT...
CVE-2021-36093MEDIUM5.3It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue...
CVE-2021-3768MEDIUM5.4bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3767MEDIUM5.4bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-25737MEDIUM4.8A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a ...
CVE-2021-25735MEDIUM6.5A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook...
CVE-2021-24611MEDIUM5.4The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in th...
CVE-2021-24603MEDIUM5.4The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an ...
CVE-2021-24601MEDIUM5.4The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, whi...
CVE-2021-24599MEDIUM6.1The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authenticatio...
CVE-2021-24591MEDIUM5.4The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to pe...
CVE-2021-24590MEDIUM5.4The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize i...
CVE-2021-24588MEDIUM6.1The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerabilit...
CVE-2021-24568MEDIUM5.4The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting i...
CVE-2021-24517MEDIUM5.4The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of i...
CVE-2021-24513MEDIUM5.4The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form ...
CVE-2021-24435MEDIUM6.1The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET par...
CVE-2021-23439MEDIUM6.1This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name ...
CVE-2021-40509MEDIUM5.4ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature.
CVE-2021-30621MEDIUM6.5Chromium: CVE-2021-30621 UI Spoofing in Autofill
CVE-2021-30619MEDIUM6.5Chromium: CVE-2021-30619 UI Spoofing in Autofill
CVE-2021-30617MEDIUM6.5Chromium: CVE-2021-30617 Policy bypass in Blink

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now