2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25938MEDIUM6.1In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validatio...
CVE-2021-24332MEDIUM4.8The Autoptimize WordPress plugin before 2.8.4 was missing proper escaping and sanitisation in some of its settings, allo...
CVE-2021-24308MEDIUM5.4The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management Sys...
CVE-2021-24307HIGH8.8The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticated u...
CVE-2021-24306MEDIUM5.4The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not ...
CVE-2021-24305MEDIUM6.1The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stor...
CVE-2021-24302MEDIUM5.4The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) v...
CVE-2021-24301MEDIUM5.4The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotja...
CVE-2021-24300MEDIUM6.1The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did n...
CVE-2021-24298MEDIUM6.1The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output b...
CVE-2021-24297MEDIUM6.1The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX ac...
CVE-2021-24296MEDIUM4.8The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege use...
CVE-2021-24294MEDIUM6.1The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape...
CVE-2021-21001MEDIUM6.5On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network a...
CVE-2021-21000HIGH7.5On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to th...
CVE-2021-33497CRITICAL9.1Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.
CVE-2021-33496MEDIUM6.1Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view.
CVE-2021-20726HIGH7.8Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privil...
CVE-2021-20725MEDIUM6.1Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows ...
CVE-2021-20724MEDIUM6.1Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a r...
CVE-2021-20723MEDIUM6.1Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed a...
CVE-2021-20722HIGH7.8Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Dow...
CVE-2021-20713HIGH7.8Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can lo...
CVE-2021-1560HIGH7.2Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a comman...
CVE-2021-1559HIGH7.2Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a comman...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now