2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-39133MEDIUM6.8Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1...
CVE-2021-34434MEDIUM5.3In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make...
CVE-2021-38343MEDIUM6.1The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB...
CVE-2021-37416MEDIUM6.1Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
CVE-2021-35061MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers...
CVE-2021-34668MEDIUM5.4The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in...
CVE-2021-22021MEDIUM5.4VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user ...
CVE-2021-3628MEDIUM5.4OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attac...
CVE-2021-33003MEDIUM5.5Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a w...
CVE-2021-32991MEDIUM4.3Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an att...
CVE-2021-27019MEDIUM4.3PuppetDB logging included potentially sensitive system information.
CVE-2021-22022MEDIUM4.9The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor ...
CVE-2021-29743MEDIUM5.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows user...
CVE-2021-29728MEDIUM4.9IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryp...
CVE-2021-27912MEDIUM5.4Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inl...
CVE-2021-27911MEDIUM6.1Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name an...
CVE-2021-27910MEDIUM6.1Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management ca...
CVE-2021-27909MEDIUM6.1For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerab...
CVE-2021-24667MEDIUM5.4A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2....
CVE-2021-24665MEDIUM5.4The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users wit...
CVE-2021-24593MEDIUM5.4The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting ...
CVE-2021-24592MEDIUM4.8The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron...
CVE-2021-24528MEDIUM5.4The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, n...
CVE-2021-24438MEDIUM6.1The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' p...
CVE-2021-24437MEDIUM6.1The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter bef...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now