2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42143CRITICAL9.1An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the han...
CVE-2021-42142CRITICAL9.8An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a ...
CVE-2021-42141CRITICAL9.8An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different...
CVE-2021-31314CRITICAL9.8File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitra...
CVE-2021-33631HIGH7.8Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Ove...
CVE-2021-33630MEDIUM5.5NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This ...
CVE-2021-4433HIGH7.5A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unkno...
CVE-2021-4434CRITICAL9.8The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 v...
CVE-2021-4227MEDIUM5.3The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source e...
CVE-2021-25117MEDIUM4.8The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options pag...
CVE-2021-24870MEDIUM6.1The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action,...
CVE-2021-24869HIGH8.8The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before u...
CVE-2021-24567MEDIUM5.4The Simple Post WordPress plugin through 1.1 does not sanitize user input when an authenticated user Text value, then it...
CVE-2021-24566HIGH8.8The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortc...
CVE-2021-24559MEDIUM5.4The Qyrr WordPress plugin before 0.7 does not escape the data-uri of the QR Code when outputting it in a src attribute, ...
CVE-2021-24433MEDIUM5.4The simple sort&search WordPress plugin through 0.0.3 does not make sure that the indexurl parameter of the shortcodes "...
CVE-2021-24432MEDIUM6.1The Advanced AJAX Product Filters WordPress plugin does not sanitise the 'term_id' POST parameter before outputting it i...
CVE-2021-24151HIGH7.2The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated ...
CVE-2021-4432HIGH7.5A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part...
CVE-2021-3600HIGH7.8It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit ...
CVE-2021-45465HIGH7.8A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation o...
CVE-2021-42028HIGH7.8A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation o...
CVE-2021-40367HIGH7.8A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation o...
CVE-2021-46901HIGH7.5examples/6lbr/apps/6lbr-webserver/httpd.c in CETIC-6LBR (aka 6lbr) 1.5.0 has a strcat stack-based buffer overflow via a ...
CVE-2021-46900HIGH7.5Sympa before 6.2.62 relies on a cookie parameter for certain security objectives, but does not ensure that this paramete...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now