2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24308MEDIUM5.4The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management Sys...
CVE-2021-24306MEDIUM5.4The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not ...
CVE-2021-24305MEDIUM6.1The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stor...
CVE-2021-24302MEDIUM5.4The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) v...
CVE-2021-24301MEDIUM5.4The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotja...
CVE-2021-24300MEDIUM6.1The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did n...
CVE-2021-24298MEDIUM6.1The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output b...
CVE-2021-24297MEDIUM6.1The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX ac...
CVE-2021-24296MEDIUM4.8The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege use...
CVE-2021-24294MEDIUM6.1The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape...
CVE-2021-21001MEDIUM6.5On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network a...
CVE-2021-33496MEDIUM6.1Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view.
CVE-2021-20725MEDIUM6.1Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows ...
CVE-2021-20724MEDIUM6.1Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a r...
CVE-2021-20723MEDIUM6.1Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed a...
CVE-2021-1558MEDIUM6.7Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privilege...
CVE-2021-1557MEDIUM6.7Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privilege...
CVE-2021-1358MEDIUM6.1A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2021-1254MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote att...
CVE-2021-33513MEDIUM5.4Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool.
CVE-2021-33512MEDIUM5.4Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document.
CVE-2021-33510MEDIUM4.3Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line...
CVE-2021-33508MEDIUM5.4Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content ite...
CVE-2021-33507MEDIUM6.1Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and ot...
CVE-2021-29681MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters i...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now