2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25264MEDIUM6.7In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administr...
CVE-2021-24327MEDIUM4.8The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Red...
CVE-2021-24326MEDIUM5.4The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable t...
CVE-2021-24325MEDIUM6.1The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflec...
CVE-2021-24324MEDIUM6.5The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to m...
CVE-2021-24323MEDIUM4.8When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output bac...
CVE-2021-24315MEDIUM4.8The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Back...
CVE-2021-24299MEDIUM6.1The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant ...
CVE-2021-24292MEDIUM5.4The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1....
CVE-2021-24290MEDIUM6.1There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticat...
CVE-2021-24288MEDIUM6.1When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to G...
CVE-2021-27342MEDIUM5.9An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0...
CVE-2021-29052MEDIUM4.3The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permi...
CVE-2021-29051MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5...
CVE-2021-29048MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 ...
CVE-2021-29046MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and...
CVE-2021-29045MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3....
CVE-2021-29044MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal ...
CVE-2021-29043MEDIUM5.9The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pa...
CVE-2021-29041MEDIUM6.5Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 all...
CVE-2021-29040MEDIUM5.3The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 2...
CVE-2021-29039MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 al...
CVE-2021-32054MEDIUM6.1Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted fi...
CVE-2021-3537MEDIUM5.9A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixe...
CVE-2021-29619MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. Passing invalid arguments (e.g., discovered via f...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now