2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39341HIGH8.2The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due...
CVE-2021-39340MEDIUM4.8The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and ...
CVE-2021-39333HIGH8.1The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce whic...
CVE-2021-38356MEDIUM6.1The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting ...
CVE-2021-20136CRITICAL9.8ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configurati...
CVE-2021-31849HIGH7.2SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacke...
CVE-2021-31848MEDIUM6.1Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a r...
CVE-2021-42917MEDIUM5.5Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper len...
CVE-2021-26740CRITICAL9.8Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code.
CVE-2021-26739CRITICAL9.8SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attri...
CVE-2021-38847HIGH8.8S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Adm...
CVE-2021-3705CRITICAL9.8Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow an unauthori...
CVE-2021-3704HIGH7.5Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow a Denial of ...
CVE-2021-3440HIGH7.8HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevati...
CVE-2021-29213MEDIUM6.7A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProL...
CVE-2021-29212CRITICAL9.8A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versio...
CVE-2021-27005HIGH7.5Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerabili...
CVE-2021-27004MEDIUM5.5System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which c...
CVE-2021-22564MEDIUM5.5For certain valid JPEG XL images with a size slightly larger than an integer number of groups (256x256 pixels) when proc...
CVE-2021-22563MEDIUM4.4Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering sp...
CVE-2021-42557HIGH7.5In Jeedom through 4.1.19, a bug allows a remote attacker to bypass API access and retrieve users credentials.
CVE-2021-25878MEDIUM6.1AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoN...
CVE-2021-25877HIGH7.2AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write f...
CVE-2021-25876MEDIUM6.1AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which...
CVE-2021-25875MEDIUM6.1AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now