2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24421MEDIUM5.4The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume ...
CVE-2021-24420MEDIUM5.4The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editi...
CVE-2021-24419MEDIUM4.8The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification ...
CVE-2021-24418MEDIUM4.8The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_posi...
CVE-2021-24409MEDIUM6.1The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attrib...
CVE-2021-24408MEDIUM5.4The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users...
CVE-2021-24385CRITICAL9.8The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp...
CVE-2021-24365MEDIUM5.4The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for ta...
CVE-2021-32707MEDIUM4.3Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by defa...
CVE-2021-32689MEDIUM6.5Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user...
CVE-2021-36381MEDIUM5.3In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's br...
CVE-2021-32705HIGH7.5Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the...
CVE-2021-32703MEDIUM5.3Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the...
CVE-2021-29822MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2021-29805MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2021-29804MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2021-29803MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2021-29794HIGH7.5IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expe...
CVE-2021-29792HIGH7.2IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and ...
CVE-2021-23390CRITICAL9.8The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
CVE-2021-23389CRITICAL9.8The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
CVE-2021-21591MEDIUM6.7Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili...
CVE-2021-21590MEDIUM6.7Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili...
CVE-2021-21589MEDIUM6.7Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local aut...
CVE-2021-21588MEDIUM4.3Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now