2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33353CRITICAL9.8Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at...
CVE-2021-33352CRITICAL9.8An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitra...
CVE-2021-33351CRITICAL9Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allo...
CVE-2021-26246Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-23232Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-23224Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-23220Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-23212Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-23199Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-23185Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.
CVE-2021-4333MEDIUM6.5The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13....
CVE-2021-4332MEDIUM6.5The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin...
CVE-2021-4331HIGH8.8The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and includin...
CVE-2021-4330HIGH8.8The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads ...
CVE-2021-44197MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo...
CVE-2021-44196MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo...
CVE-2021-36403MEDIUM5.3In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidde...
CVE-2021-36402MEDIUM5.3In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration...
CVE-2021-20251MEDIUM5.9A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks bei...
CVE-2021-36713MEDIUM6.1Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary co...
CVE-2021-36401MEDIUM4.8In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk.
CVE-2021-36400MEDIUM5.3In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.
CVE-2021-36399MEDIUM5.4In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk...
CVE-2021-36398MEDIUM5.4In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS ris...
CVE-2021-36397MEDIUM5.3In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now