2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-42391MEDIUM6.5Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compresse...
CVE-2021-42390MEDIUM6.5Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compr...
CVE-2021-42389MEDIUM6.5Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed ...
CVE-2021-39055MEDIUM5.4IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability all...
CVE-2021-39051MEDIUM6.5IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by impro...
CVE-2021-38971MEDIUM4.9IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to byp...
CVE-2021-44964MEDIUM6.3Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sa...
CVE-2021-41952MEDIUM4.8Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicio...
CVE-2021-25026MEDIUM5.5The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could...
CVE-2021-25006MEDIUM6.1The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin da...
CVE-2021-24996MEDIUM6.1The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter befor...
CVE-2021-24995MEDIUM4.8The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, whic...
CVE-2021-24982MEDIUM6.4The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting...
CVE-2021-24966MEDIUM4.9The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high p...
CVE-2021-24958MEDIUM5.4The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_...
CVE-2021-24950MEDIUM5.4The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_...
CVE-2021-24940MEDIUM6.1The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an a...
CVE-2021-24897MEDIUM5.4The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with cla...
CVE-2021-24895MEDIUM4.8The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an ...
CVE-2021-24692MEDIUM6.5The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any...
CVE-2021-43954MEDIUM4.3The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have ...
CVE-2021-46709MEDIUM6.1phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).
CVE-2021-45889MEDIUM5.4An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as dem...
CVE-2021-45888MEDIUM4.8An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of eve...
CVE-2021-42262MEDIUM6.5An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the O...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now