2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-24140HIGH7.2Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin...
CVE-2021-24137HIGH8.8Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Post...
CVE-2021-24132HIGH8.8The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functio...
CVE-2021-24131HIGH7.2Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated ...
CVE-2021-24130HIGH7.2Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page with...
CVE-2021-24125HIGH7.2Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf...
CVE-2021-24123HIGH7.2Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded fee...
CVE-2021-26237HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user ope...
CVE-2021-26235HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when ...
CVE-2021-26234HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user ope...
CVE-2021-26233HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when ...
CVE-2021-21627HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to...
CVE-2021-26236HIGH7.8FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsi...
CVE-2021-23359HIGH8.8This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an at...
CVE-2021-28419HIGH7.2The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads...
CVE-2021-3141HIGH7.8In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessi...
CVE-2021-28667HIGH7.5StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. Thi...
CVE-2021-20678HIGH8.8SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to...
CVE-2021-28660HIGH8.8rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyo...
CVE-2021-27292HIGH7.5ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attac...
CVE-2021-27291HIGH7.5In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. So...
CVE-2021-3344HIGH8.8A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are...
CVE-2021-20218HIGH7.4A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container...
CVE-2021-3127HIGH7.5NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings ar...
CVE-2021-28295HIGH7.5Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php,...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now