2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-28145MEDIUM5.4Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted su...
CVE-2021-26216MEDIUM4.3SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
CVE-2021-26215MEDIUM4.3SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
CVE-2021-24147MEDIUM5.4Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16....
CVE-2021-24138MEDIUM5.5Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para...
CVE-2021-24136MEDIUM5.4Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t...
CVE-2021-24135MEDIUM6.1Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead t...
CVE-2021-24134MEDIUM4.8Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lea...
CVE-2021-24133MEDIUM4.3Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could all...
CVE-2021-24129MEDIUM5.4Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea...
CVE-2021-24128MEDIUM5.4Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross...
CVE-2021-24127MEDIUM5.4Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions...
CVE-2021-24126MEDIUM5.4Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did ...
CVE-2021-24124MEDIUM6.1Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Una...
CVE-2021-28133MEDIUM4.3Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the par...
CVE-2021-21626MEDIUM4.3Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing fo...
CVE-2021-21625MEDIUM4.3Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTT...
CVE-2021-21624MEDIUM4.3An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with ...
CVE-2021-21623MEDIUM6.5An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with It...
CVE-2021-28420MEDIUM4.8A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and th...
CVE-2021-28418MEDIUM4.8A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and ...
CVE-2021-28417MEDIUM4.8A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t...
CVE-2021-28681MEDIUM5.3Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerCo...
CVE-2021-20676MEDIUM4.3M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve...
CVE-2021-20675MEDIUM6.5M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now