2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24342MEDIUM6.1The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (w...
CVE-2021-24340HIGH7.5The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimit...
CVE-2021-24337HIGH8.8The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is no...
CVE-2021-24336HIGH7.2The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using ...
CVE-2021-28382MEDIUM5.4Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious u...
CVE-2021-33898HIGH8.1In Invoice Ninja before 4.4.0, there is an unsafe call to unserialize() in app/Ninja/Repositories/AccountRepository.php ...
CVE-2021-33879HIGH8.1Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A malicious attacker in an MITM p...
CVE-2021-33881MEDIUM4.2On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) o...
CVE-2021-33880MEDIUM5.9The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic A...
CVE-2021-32198CRITICAL9.8EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window...
CVE-2021-31701HIGH7.5Mintty before 3.4.7 mishandles Bracketed Paste Mode.
CVE-2021-32641MEDIUM6.1auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflecte...
CVE-2021-31252MEDIUM6.1An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices f...
CVE-2021-31251CRITICAL9.8An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Tec...
CVE-2021-31250MEDIUM5.4Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU T...
CVE-2021-31249MEDIUM6.5A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology I...
CVE-2021-26928MEDIUM6.8BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products th...
CVE-2021-29500HIGH7.5bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BU...
CVE-2021-30520HIGH8.8Use after free in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install ...
CVE-2021-30519HIGH8.8Use after free in Payments in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a...
CVE-2021-30518HIGH8.8Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exp...
CVE-2021-30517HIGH8.8Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-30516HIGH8.8Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised th...
CVE-2021-30515HIGH8.8Use after free in File API in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap...
CVE-2021-30514HIGH8.8Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the ren...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now