2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24679MEDIUM6.1The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET paramete...
CVE-2021-24678MEDIUM5.4The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which...
CVE-2021-24676MEDIUM6.1The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back i...
CVE-2021-24673MEDIUM4.8The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing...
CVE-2021-24654MEDIUM5.4The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url val...
CVE-2021-24465HIGH8.1The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery sh...
CVE-2021-22557HIGH7.8SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within ...
CVE-2021-41869HIGH8.8SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
CVE-2021-41322HIGH8.8Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 dur...
CVE-2021-41285HIGH7.8Ballistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vuln...
CVE-2021-40325HIGH7.5Cobbler before 3.3.0 allows authorization bypass for modification of settings.
CVE-2021-40324HIGH7.5Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
CVE-2021-40323CRITICAL9.8Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the lo...
CVE-2021-21706MEDIUM6.5In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArch...
CVE-2021-21705MEDIUM5.3In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality vi...
CVE-2021-21704MEDIUM5.9In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, ...
CVE-2021-41861LOW3.3The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different...
CVE-2021-41864HIGH7.8prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to tri...
CVE-2021-41862CRITICAL9.8AviatorScript through 5.2.7 allows code execution via an expression that is encoded with Byte Code Engineering Library (...
CVE-2021-38109MEDIUM5.5Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An un...
CVE-2021-38108MEDIUM5.5Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing...
CVE-2021-38107MEDIUM5.5CdrCore.dll in Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a craf...
CVE-2021-41847HIGH8.8An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with ...
CVE-2021-38110HIGH7.8Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Write vulnerability when parsin...
CVE-2021-38106MEDIUM5.5UAX200.dll in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a craf...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now