2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4350 | MEDIUM | 5.3 | 0.7% | Jun 7, 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and in... |
| CVE-2021-4348 | MEDIUM | 6.1 | 0.7% | Jun 7, 2023 | The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export... |
| CVE-2021-4347 | MEDIUM | 6.5 | 0.7% | Jun 7, 2023 | The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in version... |
| CVE-2021-4345 | MEDIUM | 5.3 | 0.7% | Jun 7, 2023 | The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on th... |
| CVE-2021-4344 | MEDIUM | 5.4 | 0.5% | Jun 7, 2023 | The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1... |
| CVE-2021-4339 | MEDIUM | 5.3 | 0.9% | Jun 7, 2023 | The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisti... |
| CVE-2021-4338 | MEDIUM | 5.4 | 0.6% | Jun 7, 2023 | The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_r... |
| CVE-2021-25748 | MEDIUM | 6.5 | 0.7% | May 24, 2023 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newlin... |
| CVE-2021-46888 | MEDIUM | 5.4 | 0.8% | May 21, 2023 | An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhound... |
| CVE-2021-27131 | MEDIUM | 5.4 | 0.7% | May 16, 2023 | Moodle 3.10.1 is vulnerable to persistent/stored cross-site scripting (XSS) due to the improper input sanitization on th... |
| CVE-2021-39036 | MEDIUM | 6.1 | 0.5% | May 12, 2023 | IBM Cognos Analytics 11.1 and 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2021-46792 | MEDIUM | 5.9 | 0.4% | May 9, 2023 | Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race ... |
| CVE-2021-46759 | MEDIUM | 6.1 | 0.3% | May 9, 2023 | Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access ... |
| CVE-2021-46775 | MEDIUM | 6.8 | 0.3% | May 9, 2023 | Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, po... |
| CVE-2021-26371 | MEDIUM | 5.5 | 0.2% | May 9, 2023 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure o... |
| CVE-2021-26354 | MEDIUM | 5.5 | 0.2% | May 9, 2023 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause ... |
| CVE-2021-31711 | MEDIUM | 5.4 | 0.5% | May 9, 2023 | Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to... |
| CVE-2021-45071 | MEDIUM | 6.1 | 0.7% | Apr 25, 2023 | Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att... |
| CVE-2021-44775 | MEDIUM | 6.1 | 0.5% | Apr 25, 2023 | Cross-site scripting (XSS) issue in Website app of Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier,... |
| CVE-2021-44476 | MEDIUM | 6.8 | 0.5% | Apr 25, 2023 | A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administ... |
| CVE-2021-44465 | MEDIUM | 4.3 | 0.5% | Apr 25, 2023 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows authenticated att... |
| CVE-2021-44461 | MEDIUM | 6.1 | 0.5% | Apr 25, 2023 | Cross-site scripting (XSS) issue in Accounting app of Odoo Enterprise 13.0 through 15.0, allows remote attackers who are... |
| CVE-2021-44460 | MEDIUM | 6.5 | 0.7% | Apr 25, 2023 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier allows users with deacti... |
| CVE-2021-26947 | MEDIUM | 6.1 | 1.4% | Apr 25, 2023 | Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote att... |
| CVE-2021-26263 | MEDIUM | 6.1 | 0.6% | Apr 25, 2023 | Cross-site scripting (XSS) issue in Discuss app of Odoo Community 14.0 through 15.0, and Odoo Enterprise 14.0 through 15... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now