2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39356MEDIUM4.8The Content Staging WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation a...
CVE-2021-39354MEDIUM4.8The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end...
CVE-2021-39352HIGH7.2The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found...
CVE-2021-39348MEDIUM4.8The LearnPress WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $custom...
CVE-2021-39328MEDIUM4.8The Simple Job Board WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping on the $...
CVE-2021-39321HIGH8.8Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_...
CVE-2021-22034HIGH7.5Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.
CVE-2021-42716HIGH7.1An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when c...
CVE-2021-42715MEDIUM5.5An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines ...
CVE-2021-41160HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected ve...
CVE-2021-41159HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP cl...
CVE-2021-41146HIGH8.8qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows...
CVE-2021-35228MEDIUM4.7This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from header...
CVE-2021-35227HIGH7.8The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
CVE-2021-35225MEDIUM6.4Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath S...
CVE-2021-42327MEDIUM6.7dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 ...
CVE-2021-29883MEDIUM4.3IBM Standards Processing Engine (IBM Transformation Extender Advanced 9.0 and 10.0) does not set the secure attribute on...
CVE-2021-29873HIGH8.1IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service...
CVE-2021-28496MEDIUM6.5On systems running Arista EOS and CloudEOS with the affected release version, when using shared secret profiles the pass...
CVE-2021-20120HIGH8.8The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery...
CVE-2021-28975MEDIUM6.1WP Mailster 1.6.18.0 allows XSS when a victim opens a mail server's details in the mst_servers page, for a crafted serve...
CVE-2021-42740CRITICAL9.8The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metach...
CVE-2021-35512MEDIUM6.5An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
CVE-2021-41792MEDIUM5.3An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-tran...
CVE-2021-41791MEDIUM5.4An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An ev...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now