2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-31643MEDIUM5.4An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and...
CVE-2021-31642MEDIUM6.5A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including B...
CVE-2021-31641MEDIUM6.1An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-...
CVE-2021-3543MEDIUM6.7A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closur...
CVE-2021-3515MEDIUM6.7A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB priv...
CVE-2021-33182MEDIUM4.3Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in ...
CVE-2021-25640MEDIUM6.1In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which...
CVE-2021-24335MEDIUM6.1The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey sear...
CVE-2021-24334MEDIUM5.4The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise i...
CVE-2021-24333MEDIUM6.5The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its se...
CVE-2021-24331MEDIUM4.8The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, ...
CVE-2021-24330MEDIUM4.8The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not saniti...
CVE-2021-24329MEDIUM5.4The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settin...
CVE-2021-24328MEDIUM6.2The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any...
CVE-2021-24322MEDIUM5.4The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output ...
CVE-2021-24320MEDIUM6.1The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view,...
CVE-2021-24319MEDIUM5.4The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before...
CVE-2021-24318MEDIUM6.5The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki...
CVE-2021-24317MEDIUM6.1The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation a...
CVE-2021-24316MEDIUM6.1The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter bef...
CVE-2021-24313MEDIUM5.4The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them ...
CVE-2021-24310MEDIUM4.8The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the ...
CVE-2021-24309MEDIUM5.4The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize...
CVE-2021-23388MEDIUM5.3The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDo...
CVE-2021-20585MEDIUM5.3IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in furth...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now