2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22232 | MEDIUM | 5.4 | 0.7% | Jul 6, 2021 | HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE |
| CVE-2021-22229 | HIGH | 7.5 | 1.1% | Jul 6, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was... |
| CVE-2021-22226 | MEDIUM | 6.5 | 0.9% | Jul 6, 2021 | Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitL... |
| CVE-2021-34190 | MEDIUM | 4.8 | 0.6% | Jul 6, 2021 | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attack... |
| CVE-2021-3598 | MEDIUM | 5.5 | 0.4% | Jul 6, 2021 | There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able t... |
| CVE-2021-35440 | MEDIUM | 6.1 | 1.0% | Jul 6, 2021 | Smashing 1.3.4 is vulnerable to Cross Site Scripting (XSS). A URL for a widget can be crafted and used to execute JavaSc... |
| CVE-2021-32740 | HIGH | 7.5 | 2.2% | Jul 6, 2021 | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncon... |
| CVE-2021-31771 | — | — | — | Jul 6, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-32559 | MEDIUM | 6.5 | 1.7% | Jul 6, 2021 | An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access contr... |
| CVE-2021-27930 | MEDIUM | 5.4 | 0.6% | Jul 6, 2021 | Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to i... |
| CVE-2021-24494 | MEDIUM | 5.4 | 0.7% | Jul 6, 2021 | The WP Offload SES Lite WordPress plugin before 1.4.5 did not escape some of the fields in the Activity page of the admi... |
| CVE-2021-24451 | HIGH | 7.2 | 1.4% | Jul 6, 2021 | The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in... |
| CVE-2021-24407 | MEDIUM | 6.1 | 2.7% | Jul 6, 2021 | The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX... |
| CVE-2021-24406 | MEDIUM | 6.1 | 3.4% | Jul 6, 2021 | The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum... |
| CVE-2021-24405 | MEDIUM | 6.5 | 11.0% | Jul 6, 2021 | The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings... |
| CVE-2021-24389 | MEDIUM | 6.1 | 4.3% | Jul 6, 2021 | The WP Foodbakery WordPress plugin before 2.2, used in the FoodBakery WordPress theme before 2.2 did not properly saniti... |
| CVE-2021-24388 | MEDIUM | 5.4 | 0.3% | Jul 6, 2021 | In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we... |
| CVE-2021-24387 | MEDIUM | 6.1 | 3.7% | Jul 6, 2021 | The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search... |
| CVE-2021-24386 | MEDIUM | 5.4 | 0.7% | Jul 6, 2021 | The WP SVG images WordPress plugin before 3.4 did not sanitise the SVG files uploaded, which could allow low privilege u... |
| CVE-2021-24384 | CRITICAL | 9.8 | 2.1% | Jul 6, 2021 | The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated an... |
| CVE-2021-24375 | CRITICAL | 9.8 | 2.6% | Jul 6, 2021 | Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_qui... |
| CVE-2021-24005 | HIGH | 7.5 | 0.6% | Jul 6, 2021 | Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions befo... |
| CVE-2021-32233 | MEDIUM | 6.1 | 0.6% | Jul 6, 2021 | SmarterTools SmarterMail before Build 7776 allows XSS. |
| CVE-2021-36158 | MEDIUM | 5.9 | 0.3% | Jul 5, 2021 | In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attack... |
| CVE-2021-35331 | HIGH | 7.8 | 1.6% | Jul 5, 2021 | In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now