2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22022MEDIUM4.9The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary file read vulnerability. A malicious actor ...
CVE-2021-21774Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21773. Reason: This candidate is a reservation d...
CVE-2021-21741CRITICAL9.8There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by defaul...
CVE-2021-29743MEDIUM5.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows user...
CVE-2021-29728MEDIUM4.9IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryp...
CVE-2021-29723HIGH7.5IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou...
CVE-2021-29722HIGH7.5IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou...
CVE-2021-27913LOW3.5The function mt_rand is used to generate session tokens, this function is cryptographically flawed due to its nature bei...
CVE-2021-27912MEDIUM5.4Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack when viewing Mautic assets by utilizing inl...
CVE-2021-27911MEDIUM6.1Mautic versions before 3.3.4/4.0.0 are vulnerable to an inline JS XSS attack through the contact's first or last name an...
CVE-2021-27910MEDIUM6.1Insufficient sanitization / filtering allows for arbitrary JavaScript Injection in Mautic using the bounce management ca...
CVE-2021-27909MEDIUM6.1For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerab...
CVE-2021-37911HIGH8.8The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attacke...
CVE-2021-24667MEDIUM5.4A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2....
CVE-2021-24665MEDIUM5.4The WP Video Lightbox WordPress plugin before 1.9.3 does not escape the attributes of its shortcodes, allowing users wit...
CVE-2021-24593MEDIUM5.4The Business Hours Indicator WordPress plugin before 2.3.5 does not sanitise or escape its 'Now closed message" setting ...
CVE-2021-24592MEDIUM4.8The Sitewide Notice WP WordPress plugin before 2.3 does not sanitise some of its settings before outputting them in fron...
CVE-2021-24581HIGH8.8The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting ...
CVE-2021-24580HIGH8.8The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard ...
CVE-2021-24579HIGH8.8The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unseria...
CVE-2021-24528MEDIUM5.4The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, n...
CVE-2021-24438MEDIUM6.1The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' p...
CVE-2021-24437MEDIUM6.1The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter bef...
CVE-2021-25958HIGH7.5In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations ...
CVE-2021-39117MEDIUM4.8The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now