2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32276MEDIUM5.5An issue was discovered in faad2 through 2.10.0. A NULL pointer dereference exists in the function get_sample() located ...
CVE-2021-32275MEDIUM5.5An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigO...
CVE-2021-32274HIGH7.8An issue was discovered in faad2 through 2.10.0. A heap-buffer-overflow exists in the function sbr_qmf_synthesis_64 loca...
CVE-2021-32273HIGH7.8An issue was discovered in faad2 through 2.10.0. A stack-buffer-overflow exists in the function ftypin located in mp4rea...
CVE-2021-32272HIGH7.8An issue was discovered in faad2 before 2.10.0. A heap-buffer-overflow exists in the function stszin located in mp4read....
CVE-2021-32271HIGH7.8An issue was discovered in gpac through 20200801. A stack-buffer-overflow exists in the function DumpRawUIConfig located...
CVE-2021-32270MEDIUM5.5An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function vwid_box_del located...
CVE-2021-32269MEDIUM5.5An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function ilst_item_box_dump l...
CVE-2021-32268HIGH7.8Buffer overflow vulnerability in function gf_fprintf in os_file.c in gpac before 1.0.1 allows attackers to execute arbit...
CVE-2021-32265HIGH8.8An issue was discovered in Bento4 through v1.6.0-637. A global-buffer-overflow exists in the function AP4_MemoryByteStre...
CVE-2021-40674CRITICAL9.8An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index....
CVE-2021-39402HIGH7.2MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is...
CVE-2021-24741CRITICAL9.8The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, departmen...
CVE-2021-24663HIGH7.2The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that ...
CVE-2021-24657MEDIUM6.1The Limit Login Attempts WordPress plugin before 4.0.50 does not escape the IP addresses (which can be controlled by att...
CVE-2021-24640MEDIUM5.4The WordPress Slider Block Gutenslider plugin before 5.2.0 does not escape the minWidth attribute of a Gutenburg block, ...
CVE-2021-24639HIGH8.1The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_...
CVE-2021-24638CRITICAL9.1The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows un...
CVE-2021-24637MEDIUM5.4The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allow...
CVE-2021-24636HIGH8.1The Print My Blog WordPress Plugin before 3.4.2 does not enforce nonce (CSRF) checks, which allows attackers to make log...
CVE-2021-24635MEDIUM5.4The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the...
CVE-2021-24618MEDIUM5.4The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result ...
CVE-2021-24613MEDIUM4.8The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which co...
CVE-2021-24609MEDIUM4.8The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before output...
CVE-2021-24606HIGH8.8The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now