2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3598 | MEDIUM | 5.5 | 0.4% | Jul 6, 2021 | There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able t... |
| CVE-2021-35440 | MEDIUM | 6.1 | 1.0% | Jul 6, 2021 | Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaSc... |
| CVE-2021-32559 | MEDIUM | 6.5 | 1.7% | Jul 6, 2021 | An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access contr... |
| CVE-2021-27930 | MEDIUM | 5.4 | 0.6% | Jul 6, 2021 | Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to i... |
| CVE-2021-24494 | MEDIUM | 5.4 | 0.7% | Jul 6, 2021 | The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admi... |
| CVE-2021-24407 | MEDIUM | 6.1 | 2.7% | Jul 6, 2021 | The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX... |
| CVE-2021-24406 | MEDIUM | 6.1 | 3.4% | Jul 6, 2021 | The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum... |
| CVE-2021-24405 | MEDIUM | 6.5 | 11.0% | Jul 6, 2021 | The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings... |
| CVE-2021-24389 | MEDIUM | 6.1 | 4.3% | Jul 6, 2021 | The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly saniti... |
| CVE-2021-24388 | MEDIUM | 5.4 | 0.3% | Jul 6, 2021 | In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we... |
| CVE-2021-24387 | MEDIUM | 6.1 | 3.7% | Jul 6, 2021 | The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search... |
| CVE-2021-24386 | MEDIUM | 5.4 | 0.7% | Jul 6, 2021 | The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege u... |
| CVE-2021-32233 | MEDIUM | 6.1 | 0.6% | Jul 6, 2021 | SmarterTools SmarterMail before Build 7776 allows XSS. |
| CVE-2021-36158 | MEDIUM | 5.9 | 0.3% | Jul 5, 2021 | In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attack... |
| CVE-2021-23401 | MEDIUM | 6.1 | 1.1% | Jul 5, 2021 | This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL val... |
| CVE-2021-33192 | MEDIUM | 6.1 | 2.9% | Jul 5, 2021 | A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain pa... |
| CVE-2021-35208 | MEDIUM | 5.4 | 1.3% | Jul 2, 2021 | An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before ... |
| CVE-2021-35207 | MEDIUM | 6.1 | 3.3% | Jul 2, 2021 | An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS v... |
| CVE-2021-34807 | MEDIUM | 6.1 | 1.0% | Jul 2, 2021 | An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the ... |
| CVE-2021-33889 | MEDIUM | 6.8 | 0.3% | Jul 2, 2021 | OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data... |
| CVE-2021-32738 | MEDIUM | 6.5 | 0.5% | Jul 2, 2021 | js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` func... |
| CVE-2021-32737 | MEDIUM | 4.8 | 0.7% | Jul 2, 2021 | Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41... |
| CVE-2021-31874 | MEDIUM | 5.9 | 4.3% | Jul 2, 2021 | Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information a... |
| CVE-2021-32735 | MEDIUM | 5.4 | 0.5% | Jul 2, 2021 | Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in t... |
| CVE-2021-36131 | MEDIUM | 4.8 | 0.4% | Jul 2, 2021 | An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a priv... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now