2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21750HIGH7.8ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task mod...
CVE-2021-43856MEDIUM5.4Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through...
CVE-2021-43855MEDIUM5.4Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through...
CVE-2021-43845CRITICAL9.1PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR messa...
CVE-2021-38961MEDIUM6.1IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c...
CVE-2021-45232CRITICAL9.8In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the ...
CVE-2021-45339HIGH7.8Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "...
CVE-2021-45338HIGH7.8Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privi...
CVE-2021-45337HIGH8.8Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with ...
CVE-2021-45336HIGH8.8Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed co...
CVE-2021-45335HIGH8.8Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to con...
CVE-2021-4173HIGH7.8vim is vulnerable to Use After Free
CVE-2021-24998HIGH7.5The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly gen...
CVE-2021-24997MEDIUM6.5The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any...
CVE-2021-24992MEDIUM4.8The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before out...
CVE-2021-24988MEDIUM5.4The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the Syste...
CVE-2021-24984MEDIUM6.1The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved paramete...
CVE-2021-24980MEDIUM6.1The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter befor...
CVE-2021-24979MEDIUM6.1The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an a...
CVE-2021-24969MEDIUM5.4The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputti...
CVE-2021-24967MEDIUM6.1The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead valu...
CVE-2021-24902MEDIUM4.8The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publis...
CVE-2021-24797MEDIUM6.1The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events befor...
CVE-2021-24753HIGH7.2The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the p...
CVE-2021-45711HIGH7.5An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now