2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24164MEDIUM4.3In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri...
CVE-2021-24158MEDIUM6.5Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f...
CVE-2021-24157MEDIUM5.4Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no che...
CVE-2021-24156MEDIUM5.4Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inj...
CVE-2021-24154MEDIUM4.9The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f...
CVE-2021-24153MEDIUM5.4A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had bui...
CVE-2021-24152MEDIUM6.1The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
CVE-2021-30109MEDIUM6.1Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads t...
CVE-2021-30058MEDIUM6.1Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script i...
CVE-2021-30057MEDIUM4.8A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/re...
CVE-2021-30056MEDIUM5.4Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web scr...
CVE-2021-21533MEDIUM4.3Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a den...
CVE-2021-21532MEDIUM6.3Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be p...
CVE-2021-21529MEDIUM5.5Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malic...
CVE-2021-30074MEDIUM6.1docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code...
CVE-2021-30126MEDIUM6.5Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightm...
CVE-2021-30125MEDIUM6.1Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.
CVE-2021-28941MEDIUM5.3Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a reque...
CVE-2021-3374MEDIUM5.3Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involvin...
CVE-2021-29661MEDIUM5.4Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parame...
CVE-2021-1879MEDIUM6.1This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and i...
CVE-2021-1801MEDIUM6.5This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security U...
CVE-2021-1800MEDIUM5.5A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application...
CVE-2021-1799MEDIUM6.5A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Secur...
CVE-2021-1797MEDIUM5.5The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now