2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22232MEDIUM5.4HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
CVE-2021-22229HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was...
CVE-2021-22226MEDIUM6.5Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitL...
CVE-2021-34190MEDIUM4.8A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attack...
CVE-2021-3598MEDIUM5.5There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able t...
CVE-2021-35440MEDIUM6.1Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaSc...
CVE-2021-32740HIGH7.5Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncon...
CVE-2021-31771Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-32559MEDIUM6.5An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access contr...
CVE-2021-27930MEDIUM5.4Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to i...
CVE-2021-24494MEDIUM5.4The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admi...
CVE-2021-24451HIGH7.2The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in...
CVE-2021-24407MEDIUM6.1The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX...
CVE-2021-24406MEDIUM6.1The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum...
CVE-2021-24405MEDIUM6.5The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings...
CVE-2021-24389MEDIUM6.1The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly saniti...
CVE-2021-24388MEDIUM5.4In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we...
CVE-2021-24387MEDIUM6.1The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search...
CVE-2021-24386MEDIUM5.4The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege u...
CVE-2021-24384CRITICAL9.8The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an...
CVE-2021-24375CRITICAL9.8Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui...
CVE-2021-24005HIGH7.5Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions befo...
CVE-2021-32233MEDIUM6.1SmarterTools SmarterMail before Build 7776 allows XSS.
CVE-2021-36158MEDIUM5.9In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attack...
CVE-2021-35331HIGH7.8In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now