2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36350HIGH7.5Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authen...
CVE-2021-36341MEDIUM5.5Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated...
CVE-2021-36337HIGH7.4Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 whi...
CVE-2021-36336CRITICAL9.8Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticat...
CVE-2021-36318MEDIUM6.7Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged...
CVE-2021-36317MEDIUM6.7Dell EMC Avamar Server version 19.4 contains a plain-text password storage vulnerability in AvInstaller. A local attacke...
CVE-2021-36316HIGH7.2Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability ...
CVE-2021-45091MEDIUM4.3Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
CVE-2021-45090CRITICAL9.8Stormshield Endpoint Security before 2.1.2 allows remote code execution.
CVE-2021-45089MEDIUM5.2Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
CVE-2021-4139CRITICAL9pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-45255CRITICAL9.8The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payl...
CVE-2021-45253CRITICAL9.8The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL inje...
CVE-2021-45252CRITICAL9.8Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications...
CVE-2021-24981HIGH7.5The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leadi...
CVE-2021-24956MEDIUM6.1The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sSh...
CVE-2021-24941MEDIUM6.1The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape th...
CVE-2021-24907MEDIUM6.1The Contact Form, Drag and Drop Form Builder for WordPress plugin before 1.8.0 does not escape the status parameter befo...
CVE-2021-24849CRITICAL9.8The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin before 3.4.12, available to unauthenticate...
CVE-2021-24846HIGH8.8The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_a...
CVE-2021-24750HIGH8.8The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refU...
CVE-2021-24739HIGH8.1The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb...
CVE-2021-24738MEDIUM5.4The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which co...
CVE-2021-24578MEDIUM6.1The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting bac...
CVE-2021-45451HIGH7.5In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now