2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34623CRITICAL9.8A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress Wo...
CVE-2021-34622HIGH8.8A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP...
CVE-2021-34621CRITICAL9.8A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr...
CVE-2021-34620HIGH8.8The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Si...
CVE-2021-25952CRITICAL9.8Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial o...
CVE-2021-22555HIGH7.8A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an ...
CVE-2021-22225MEDIUM5.4Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-...
CVE-2021-22224MEDIUM6.5A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 ...
CVE-2021-26039MEDIUM6.1An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to...
CVE-2021-26038HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL...
CVE-2021-26037MEDIUM5.3An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions w...
CVE-2021-26036HIGH7.5An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups t...
CVE-2021-26035MEDIUM6.1An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads t...
CVE-2021-22231MEDIUM4.3A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access...
CVE-2021-22230HIGH7.2Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability a...
CVE-2021-22227MEDIUM6.1A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to...
CVE-2021-20780HIGH8.8Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote at...
CVE-2021-20779HIGH8.8Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3....
CVE-2021-20777MEDIUM4.3Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2...
CVE-2021-20776CRITICAL9.8Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction an...
CVE-2021-20739HIGH8.8WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, a...
CVE-2021-20738MEDIUM6.5WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain se...
CVE-2021-35039HIGH7.8kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONF...
CVE-2021-22228MEDIUM6.5An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13...
CVE-2021-22223MEDIUM6.1Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted featu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now