2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39931MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions start...
CVE-2021-39930MEDIUM4.3Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 1...
CVE-2021-39919MEDIUM4.4In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all ...
CVE-2021-39918MEDIUM4.3Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from...
CVE-2021-39917MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions start...
CVE-2021-39916MEDIUM4.3Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the conf...
CVE-2021-39915MEDIUM5.3Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all ...
CVE-2021-39910MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions start...
CVE-2021-22279CRITICAL9.8A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and mod...
CVE-2021-44966CRITICAL9.8SQL injection bypass authentication vulnerability in PHPGURUKUL Employee Record Management System 1.2 via index.php. An ...
CVE-2021-44965HIGH7.5Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 Th...
CVE-2021-36169MEDIUM6A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unaut...
CVE-2021-43117CRITICAL9.8fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
CVE-2021-42549MEDIUM6.1Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenti...
CVE-2021-42548MEDIUM6.1Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows una...
CVE-2021-42547MEDIUM6.1Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unau...
CVE-2021-42546MEDIUM6.1Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unau...
CVE-2021-24972MEDIUM4.8The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users...
CVE-2021-24970HIGH7.2The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using...
CVE-2021-24955MEDIUM6.1The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data para...
CVE-2021-24954MEDIUM6.1The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape ...
CVE-2021-24951CRITICAL9.8The LearnPress WordPress plugin before 4.1.4 does not sanitise, validate and escape the id parameter before using it in ...
CVE-2021-24946CRITICAL9.8The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the time parameter before usi...
CVE-2021-24945HIGH8The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the l...
CVE-2021-24932MEDIUM6.1The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id par...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now