2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29024HIGH7.5In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing a...
CVE-2021-29023MEDIUM5.3InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mech...
CVE-2021-32618MEDIUM6.1The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an i...
CVE-2021-32617MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-32456MEDIUM6.5SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the au...
CVE-2021-32454HIGH8.8SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could mod...
CVE-2021-23384MEDIUM5.4The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slas...
CVE-2021-3524MEDIUM6.5A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability...
CVE-2021-33041MEDIUM6.1vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require...
CVE-2021-32455MEDIUM6.5SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of servi...
CVE-2021-32453LOW3.3SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network, to access via HTTP to the int...
CVE-2021-29747HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vul...
CVE-2021-25264MEDIUM6.7In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administr...
CVE-2021-24327MEDIUM4.8The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Red...
CVE-2021-24326MEDIUM5.4The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable t...
CVE-2021-24325MEDIUM6.1The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflec...
CVE-2021-24324MEDIUM6.5The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to m...
CVE-2021-24323MEDIUM4.8When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output bac...
CVE-2021-24315MEDIUM4.8The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Back...
CVE-2021-24314CRITICAL9.8The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing pag...
CVE-2021-24299MEDIUM6.1The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant ...
CVE-2021-24295HIGH7.5It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiS...
CVE-2021-24292MEDIUM5.4The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1....
CVE-2021-24290MEDIUM6.1There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticat...
CVE-2021-24289HIGH8.8There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authentic...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now