2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-4350MEDIUM5.3The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and in...
CVE-2021-4348MEDIUM6.1The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export...
CVE-2021-4347MEDIUM6.5The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in version...
CVE-2021-4345MEDIUM5.3The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on th...
CVE-2021-4344MEDIUM5.4The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1...
CVE-2021-4339MEDIUM5.3The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisti...
CVE-2021-4338MEDIUM5.4The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_r...
CVE-2021-25748MEDIUM6.5A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newlin...
CVE-2021-46888MEDIUM5.4An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhound...
CVE-2021-27131MEDIUM5.4Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on th...
CVE-2021-39036MEDIUM6.1IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2021-46792MEDIUM5.9Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race ...
CVE-2021-46759MEDIUM6.1Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access ...
CVE-2021-46775MEDIUM6.8Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, po...
CVE-2021-26371MEDIUM5.5A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure o...
CVE-2021-26354MEDIUM5.5Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause ...
CVE-2021-31711MEDIUM5.4Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to...
CVE-2021-45071MEDIUM6.1Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att...
CVE-2021-44775MEDIUM6.1Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier,...
CVE-2021-44476MEDIUM6.8A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ...
CVE-2021-44465MEDIUM4.3Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated att...
CVE-2021-44461MEDIUM6.1Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are...
CVE-2021-44460MEDIUM6.5Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deacti...
CVE-2021-26947MEDIUM6.1Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att...
CVE-2021-26263MEDIUM6.1Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now