2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-28601MEDIUM5.5Adobe After Effects version 18.2 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a sp...
CVE-2021-28600MEDIUM5.5Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a special...
CVE-2021-39602MEDIUM6.5A Buffer Overflow vulnerabilty exists in Miniftpd 1.0 in the do_mkd function in the ftpproto.c file, which could let a r...
CVE-2021-39599MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/s...
CVE-2021-39609MEDIUM5.4Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function.
CVE-2021-22253MEDIUM5.4Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary ac...
CVE-2021-22252MEDIUM6.5A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access...
CVE-2021-22251MEDIUM4.3Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to a...
CVE-2021-22249MEDIUM4.3A verbose error message in GitLab EE affecting all versions since 12.2 could disclose the private email address of a use...
CVE-2021-22248MEDIUM5.3Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized use...
CVE-2021-39140MEDIUM6.3XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo...
CVE-2021-3731MEDIUM4.7LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This...
CVE-2021-3730MEDIUM6.5firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3729MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3728MEDIUM6.5firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-33598MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component u...
CVE-2021-24658MEDIUM4.8The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing hi...
CVE-2021-24574MEDIUM4.8The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privile...
CVE-2021-24571MEDIUM5.4The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when g...
CVE-2021-24564MEDIUM5.4The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outp...
CVE-2021-24561MEDIUM5.4The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in t...
CVE-2021-24558MEDIUM5.4The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise,...
CVE-2021-24556MEDIUM6.1The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sani...
CVE-2021-24549MEDIUM4.9The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths...
CVE-2021-24547MEDIUM5.4The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now