2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36408MEDIUM5.5An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265...
CVE-2021-35452MEDIUM6.5An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
CVE-2021-29454HIGH8.8Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2021-21408HIGH8.8Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2021-44458CRITICAL9.6Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website c...
CVE-2021-43951MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43949MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43297CRITICAL9.8A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malic...
CVE-2021-25054HIGH8.8The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL state...
CVE-2021-25053HIGH8.8The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file wit...
CVE-2021-25052HIGH8.8The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary ...
CVE-2021-25051HIGH8.8The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file...
CVE-2021-25047MEDIUM6.1The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulner...
CVE-2021-25043MEDIUM6.1The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it ...
CVE-2021-25032CRITICAL9.8The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1...
CVE-2021-24949CRITICAL9.8The "WP Search Filters" widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise an...
CVE-2021-24948HIGH7.5The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_...
CVE-2021-24862HIGH7.2The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action befo...
CVE-2021-23218HIGH7.5When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could b...
CVE-2021-23154HIGH7.8In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided argu...
CVE-2021-44586HIGH7.5An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that ...
CVE-2021-46166MEDIUM6.5Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the da...
CVE-2021-46165HIGH7.8Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but...
CVE-2021-46164HIGH8.8Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete...
CVE-2021-46163MEDIUM6.1Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now