2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26588CRITICAL9.8A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 S...
CVE-2021-25633HIGH7.5LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alt...
CVE-2021-22263MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr...
CVE-2021-20122HIGH7.2The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vu...
CVE-2021-20121MEDIUM4The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file rea...
CVE-2021-39317HIGH8.8A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads...
CVE-2021-37123CRITICAL9.8There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when ...
CVE-2021-27665HIGH7.5An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a spe...
CVE-2021-27664CRITICAL9.8Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVisi...
CVE-2021-0583HIGH7.3In onCreate of BluetoothPairingDialog, there is a possible way to enable Bluetooth without user consent due to a tapjack...
CVE-2021-40541MEDIUM6.1PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descri...
CVE-2021-40191MEDIUM5.4Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all up...
CVE-2021-40543CRITICAL9.8Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at ...
CVE-2021-40542MEDIUM6.1Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja...
CVE-2021-29006MEDIUM6.5rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any ...
CVE-2021-29005HIGH8.8Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute ch...
CVE-2021-29004HIGH8.8rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-...
CVE-2021-40888MEDIUM5.4Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in...
CVE-2021-40887CRITICAL9.8Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for ...
CVE-2021-40886MEDIUM6.5Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2...
CVE-2021-40884HIGH8.1Projectsend version r1295 is affected by sensitive information disclosure. Because of not checking authorization in ids ...
CVE-2021-24737MEDIUM4.8The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow mess...
CVE-2021-24720MEDIUM5.4The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Sc...
CVE-2021-24719MEDIUM6.1The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability...
CVE-2021-24712MEDIUM5.4The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new cal...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now