2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20735MEDIUM6.1Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier...
CVE-2021-20734MEDIUM6.1Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbit...
CVE-2021-20733MEDIUM6.1Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions fro...
CVE-2021-34389MEDIUM5Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorre...
CVE-2021-34387MEDIUM6.7The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where th...
CVE-2021-34386MEDIUM6.7Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation ca...
CVE-2021-32698MEDIUM4.9eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET r...
CVE-2021-24383MEDIUM5.4The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the M...
CVE-2021-24379MEDIUM5.3The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not p...
CVE-2021-24378MEDIUM4.8The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded v...
CVE-2021-24374MEDIUM5.3The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image ga...
CVE-2021-24373MEDIUM6.1The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyvalue...
CVE-2021-24372MEDIUM6.1The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['RE...
CVE-2021-24369MEDIUM5.4In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, h...
CVE-2021-24367MEDIUM5.4The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (X...
CVE-2021-24366MEDIUM5.4The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and es...
CVE-2021-24364MEDIUM6.1The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather...
CVE-2021-24339MEDIUM5.4The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cros...
CVE-2021-24338MEDIUM5.4The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cros...
CVE-2021-32697MEDIUM5.3neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form s...
CVE-2021-21422MEDIUM6.1mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: h...
CVE-2021-0521MEDIUM5.5In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check...
CVE-2021-0504MEDIUM6.5In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This c...
CVE-2021-29060MEDIUM5.3A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below whic...
CVE-2021-28833MEDIUM6.1Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-287...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now