2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37840HIGH8.8aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a...
CVE-2021-37167CRITICAL9.8An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by releas...
CVE-2021-37166HIGH7.5A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus P...
CVE-2021-37164CRITICAL9.8A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released ver...
CVE-2021-37163CRITICAL9.8An insecure permissions issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus operated by released ver...
CVE-2021-37162CRITICAL9.8A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released ver...
CVE-2021-37161CRITICAL9.8A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, o...
CVE-2021-37160CRITICAL9.8A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released...
CVE-2021-20332MEDIUM4.4Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in...
CVE-2021-37216MEDIUM6.1QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript w...
CVE-2021-37165CRITICAL9.8A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released ver...
CVE-2021-34575HIGH7.5In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an unauthenticated user can enumerate valid users by ...
CVE-2021-34574MEDIUM4.3In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 a...
CVE-2021-33527CRITICAL9.8In MB connect line mbDIALUP versions <= 3.9R0.0 a remote attacker can send a specifically crafted HTTP request to the se...
CVE-2021-33526HIGH7.8In MB connect line mbDIALUP versions <= 3.9R0.0 a low privileged local attacker can send a command to the service runnin...
CVE-2021-24504MEDIUM6.1The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Fi...
CVE-2021-24503MEDIUM5.4The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode...
CVE-2021-24498MEDIUM6.1The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET param...
CVE-2021-24496MEDIUM6.1The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and success...
CVE-2021-24492HIGH8.8The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, avai...
CVE-2021-24488MEDIUM6.1The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not prope...
CVE-2021-24484HIGH7.2The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did n...
CVE-2021-24483HIGH7.2The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did n...
CVE-2021-24481MEDIUM4.8The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an a...
CVE-2021-24480MEDIUM4.8The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now