2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3645CRITICAL9.8merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-34346CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite...
CVE-2021-34345CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploite...
CVE-2021-34344CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulne...
CVE-2021-34343HIGH7.2A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If expl...
CVE-2021-28816HIGH8.8A stack buffer overflow vulnerability has been reported to affect QNAP device running QTS, QuTScloud, QuTS hero. If expl...
CVE-2021-28813HIGH7.5A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP...
CVE-2021-40839HIGH7.5The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabl...
CVE-2021-39206HIGH8.6Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, contains two authorization re...
CVE-2021-39204HIGH7.5Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting...
CVE-2021-39203MEDIUM6.5WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database...
CVE-2021-39202MEDIUM5.4WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database...
CVE-2021-39201MEDIUM5.4WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database...
CVE-2021-39200MEDIUM5.3WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database...
CVE-2021-39162HIGH8.6Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if a...
CVE-2021-32724CRITICAL9.9check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [...
CVE-2021-38325MEDIUM6.1The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter fou...
CVE-2021-38324HIGH7.5The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shor...
CVE-2021-38323MEDIUM6.1The RentPress WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selections parameter found in the...
CVE-2021-38322MEDIUM6.1The Twitter Friends Widget WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the pmc_TF_user and pmc_...
CVE-2021-38321MEDIUM6.1The Custom Menu Plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the selected_menu parameter ...
CVE-2021-38320MEDIUM6.1The simpleSAMLphp Authentication WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_S...
CVE-2021-38319MEDIUM6.1The More From Google WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_S...
CVE-2021-38318MEDIUM6.1The 3D Cover Carousel WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/cov...
CVE-2021-38317MEDIUM6.1The Konnichiwa! Membership WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the plan_id parameter in...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now