2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-29424HIGH7.5The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of...
CVE-2021-30130HIGH7.5phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
CVE-2021-28142HIGH8.8CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
CVE-2021-28874HIGH7.8SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode ...
CVE-2021-28075HIGH7.5iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to ob...
CVE-2021-27343HIGH7.5SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent)....
CVE-2021-28172HIGH7.5There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers ...
CVE-2021-30163HIGH7.5Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal ...
CVE-2021-30162HIGH7.1An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS servic...
CVE-2021-28204HIGH7.2The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter th...
CVE-2021-28203HIGH7.2The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As o...
CVE-2021-30141HIGH7.5Module/Settings/UserExport.php in Friendica through 2021.01 allows settings/userexport to be used by anonymous users, as...
CVE-2021-20305HIGH8.1A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, ED...
CVE-2021-24209HIGH7.2The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due ...
CVE-2021-24184HIGH8.8Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprot...
CVE-2021-24174HIGH8.1The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in ...
CVE-2021-24170HIGH7.5The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than...
CVE-2021-24167HIGH7.5When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send ...
CVE-2021-24163HIGH8.8The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it ha...
CVE-2021-24162HIGH8.8In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini...
CVE-2021-24161HIGH8.8In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini...
CVE-2021-24160HIGH8.8In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing ma...
CVE-2021-24159HIGH8.8Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a reques...
CVE-2021-24155HIGH7.2The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported fi...
CVE-2021-24150HIGH7.5The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now