2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24762CRITICAL9.8The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using...
CVE-2021-24761MEDIUM6.5The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not ha...
CVE-2021-24707MEDIUM4.8The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi...
CVE-2021-24686MEDIUM4.8The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in...
CVE-2021-24648MEDIUM6.1The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before ...
CVE-2021-43859HIGH7.5XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a ...
CVE-2021-41040HIGH7.5In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-...
CVE-2021-3534Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-34981. Reason: This candidate is a reservation d...
CVE-2021-46669HIGH7.5MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is us...
CVE-2021-46668MEDIUM5.5MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact ...
CVE-2021-46667MEDIUM5.5MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
CVE-2021-46666MEDIUM5.5MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE c...
CVE-2021-46665MEDIUM5.5MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
CVE-2021-46664MEDIUM5.5MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
CVE-2021-46663MEDIUM5.5MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
CVE-2021-46662MEDIUM5.5MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with...
CVE-2021-46661MEDIUM5.5MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common t...
CVE-2021-46459HIGH7.5Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source...
CVE-2021-44114MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows r...
CVE-2021-42635HIGH8.1PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code e...
CVE-2021-42631HIGH8.1PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code...
CVE-2021-46458HIGH7.5Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post...
CVE-2021-40042MEDIUM6.5There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process an...
CVE-2021-40033MEDIUM5.5There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software...
CVE-2021-31617CRITICAL9.8In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 thro...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now