2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37618MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37616MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37623MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-34334MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-32815MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-25954MEDIUM4.3In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthor...
CVE-2021-29714MEDIUM6.5IBM Content Navigator 3.0.CD could allow a malicious user to cause a denial of service due to improper input validation....
CVE-2021-21740LOW2.4There is an information leak vulnerability in the digital media player (DMS) of ZTE's residential gateway product. The a...
CVE-2021-20349MEDIUM5.3IBM Tivoli Workload Scheduler 9.4 and 9.5 is vulnerable to a stack-based buffer overflow, caused by improper bounds chec...
CVE-2021-33256HIGH8.8A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be e...
CVE-2021-37788MEDIUM5.4A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect t...
CVE-2021-37573MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS...
CVE-2021-36798HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allow...
CVE-2021-34661MEDIUM4.7The WP Fusion Lite WordPress plugin is vulnerable to Cross-Site Request Forgery via the `show_logs_section` function fou...
CVE-2021-34660MEDIUM6.1The WP Fusion Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the startdate parameter found in...
CVE-2021-22910CRITICAL9.8A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an ...
CVE-2021-38290HIGH8.1A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel...
CVE-2021-37215MEDIUM4.3The employee management page of Flygo contains an Insecure Direct Object Reference (IDOR) vulnerability. After being aut...
CVE-2021-37214HIGH8.8The employee management page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authen...
CVE-2021-37213MEDIUM4.3The check-in record page of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authentica...
CVE-2021-37212MEDIUM5.4The bulletin function of Flygo contains Insecure Direct Object Reference (IDOR) vulnerability. After being authenticated...
CVE-2021-37211MEDIUM5.4The bulletin function of Flygo does not filter special characters while a new announcement is added. Remoter attackers c...
CVE-2021-24522MEDIUM6.1The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before...
CVE-2021-24521HIGH7.2The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values from...
CVE-2021-24520HIGH8.8The Stock in & out WordPress plugin through 1.0.4 lacks proper sanitization before passing variables to an SQL request, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now