2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24533MEDIUM4.8The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege u...
CVE-2021-24531MEDIUM5.4The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site script...
CVE-2021-24529MEDIUM5.4The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for...
CVE-2021-24524MEDIUM4.8The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level s...
CVE-2021-24506HIGH8.8The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape...
CVE-2021-24497HIGH7.2The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user ...
CVE-2021-24486MEDIUM5.4The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the ali...
CVE-2021-35940HIGH7.1An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE...
CVE-2021-39291HIGH8.8Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, ...
CVE-2021-39290CRITICAL9.8Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4...
CVE-2021-39289HIGH7.5Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmwa...
CVE-2021-39245HIGH7.5Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affec...
CVE-2021-39244HIGH8.8Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xto...
CVE-2021-39243MEDIUM6.5Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. Th...
CVE-2021-38598CRITICAL9.1OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbrid...
CVE-2021-37750MEDIUM6.5The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer...
CVE-2021-39371HIGH7.5An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server ...
CVE-2021-39368MEDIUM6.1Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter.
CVE-2021-39367MEDIUM5.3Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection.
CVE-2021-39365MEDIUM5.9In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects ...
CVE-2021-39362MEDIUM6.1An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEAT...
CVE-2021-39361MEDIUM5.9In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSyn...
CVE-2021-39360MEDIUM5.9In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync ob...
CVE-2021-39359MEDIUM5.9In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync ob...
CVE-2021-39358MEDIUM5.9In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now