2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24547MEDIUM5.4The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.
CVE-2021-24533MEDIUM4.8The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege u...
CVE-2021-24531MEDIUM5.4The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site script...
CVE-2021-24529MEDIUM5.4The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for...
CVE-2021-24524MEDIUM4.8The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level s...
CVE-2021-24486MEDIUM5.4The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the ali...
CVE-2021-39243MEDIUM6.5Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. Th...
CVE-2021-37750MEDIUM6.5The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer...
CVE-2021-39368MEDIUM6.1Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.
CVE-2021-39367MEDIUM5.3Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
CVE-2021-39365MEDIUM5.9In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects ...
CVE-2021-39362MEDIUM6.1An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEAT...
CVE-2021-39361MEDIUM5.9In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSyn...
CVE-2021-39360MEDIUM5.9In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync ob...
CVE-2021-39359MEDIUM5.9In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync ob...
CVE-2021-39358MEDIUM5.9In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync...
CVE-2021-36008MEDIUM5.5Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when parsing a specially c...
CVE-2021-35985MEDIUM5.5Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a...
CVE-2021-35984MEDIUM6.5Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a...
CVE-2021-28593MEDIUM5.5Adobe Illustrator version 25.2.3 (and earlier) is affected by a Use After Free vulnerability when parsing a specially cr...
CVE-2021-22255MEDIUM6.5SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server n...
CVE-2021-22254MEDIUM4.3Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE ...
CVE-2021-22246MEDIUM6.5A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abuse...
CVE-2021-22238MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS ...
CVE-2021-34228MEDIUM6.1Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now