2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-37620MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37619MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37618MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37616MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37623MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-34334MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-32815MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-25954MEDIUM4.3In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthor...
CVE-2021-29714MEDIUM6.5IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation....
CVE-2021-20349MEDIUM5.3IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds chec...
CVE-2021-37788MEDIUM5.4A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect t...
CVE-2021-37573MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS...
CVE-2021-34661MEDIUM4.7The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function fou...
CVE-2021-34660MEDIUM6.1The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in...
CVE-2021-37215MEDIUM4.3The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being aut...
CVE-2021-37213MEDIUM4.3The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authentica...
CVE-2021-37212MEDIUM5.4The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated...
CVE-2021-37211MEDIUM5.4The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers c...
CVE-2021-24522MEDIUM6.1The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before...
CVE-2021-24509MEDIUM5.4The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing ...
CVE-2021-24505MEDIUM5.4The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issue...
CVE-2021-24502MEDIUM4.8The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the p...
CVE-2021-24495MEDIUM6.1The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter befo...
CVE-2021-24467MEDIUM6.5The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows atta...
CVE-2021-24304MEDIUM6.1The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, lea...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now