2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3598MEDIUM5.5There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able t...
CVE-2021-35440MEDIUM6.1Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaSc...
CVE-2021-32559MEDIUM6.5An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access contr...
CVE-2021-27930MEDIUM5.4Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to i...
CVE-2021-24494MEDIUM5.4The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admi...
CVE-2021-24407MEDIUM6.1The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX...
CVE-2021-24406MEDIUM6.1The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum...
CVE-2021-24405MEDIUM6.5The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings...
CVE-2021-24389MEDIUM6.1The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly saniti...
CVE-2021-24388MEDIUM5.4In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we...
CVE-2021-24387MEDIUM6.1The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search...
CVE-2021-24386MEDIUM5.4The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege u...
CVE-2021-32233MEDIUM6.1SmarterTools SmarterMail before Build 7776 allows XSS.
CVE-2021-36158MEDIUM5.9In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attack...
CVE-2021-23401MEDIUM6.1This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL val...
CVE-2021-33192MEDIUM6.1A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain pa...
CVE-2021-35208MEDIUM5.4An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before ...
CVE-2021-35207MEDIUM6.1An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS v...
CVE-2021-34807MEDIUM6.1An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the ...
CVE-2021-33889MEDIUM6.8OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data...
CVE-2021-32738MEDIUM6.5js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` func...
CVE-2021-32737MEDIUM4.8Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41...
CVE-2021-31874MEDIUM5.9Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information a...
CVE-2021-32735MEDIUM5.4Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in t...
CVE-2021-36131MEDIUM4.8An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a priv...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now