2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-39144HIGH8.5XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo...
CVE-2021-39141HIGH8.5XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo...
CVE-2021-39139HIGH8.8XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo...
CVE-2021-29802HIGH7.5IBM Security SOAR performs an operation at a privilege level that is higher than the minimum level required, which creat...
CVE-2021-29704HIGH7.5IBM Security SOAR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens...
CVE-2021-24602HIGH8.8The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set...
CVE-2021-24565HIGH8.8The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings,...
CVE-2021-24562HIGH7.5The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 ...
CVE-2021-24557HIGH7.2The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped b...
CVE-2021-24555HIGH8.8The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter wh...
CVE-2021-24554HIGH7.2The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter be...
CVE-2021-24553HIGH7.2The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before u...
CVE-2021-24552HIGH7.2The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parame...
CVE-2021-24550HIGH7.2The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter befor...
CVE-2021-24506HIGH8.8The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape...
CVE-2021-24497HIGH7.2The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user ...
CVE-2021-35940HIGH7.1An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE...
CVE-2021-39291HIGH8.8Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, ...
CVE-2021-39289HIGH7.5Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmwa...
CVE-2021-39245HIGH7.5Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affec...
CVE-2021-39244HIGH8.8Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xto...
CVE-2021-39371HIGH7.5An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server ...
CVE-2021-36015HIGH7.8Adobe Media Encoder version 15.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially...
CVE-2021-36011HIGH7.8Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained w...
CVE-2021-36009HIGH7.8Adobe Illustrator version 25.2.3 (and earlier) is affected by an memory corruption vulnerability when parsing a speciall...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now