2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-44566MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 4.3 via the SanitizeMarkDown function in ProgramF...
CVE-2021-44565MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Secur...
CVE-2021-43724MEDIUM4.8A Cross Site Scripting (XSS) vulnerability exits in Subrion CMS through 4.2.1 in the Create Page functionality of the ad...
CVE-2021-43943MEDIUM4.8Affected versions of Atlassian Jira Service Management Server and Data Center allow attackers with administrator privile...
CVE-2021-26092MEDIUM6.1Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 throug...
CVE-2021-4115MEDIUM5.5There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor ...
CVE-2021-44568MEDIUM6.5Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via ...
CVE-2021-44141MEDIUM4.3All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file...
CVE-2021-27796MEDIUM6.5A vulnerability in Brocade Fabric OS versions before Brocade Fabric OS v8.0.1b, v7.4.1d could allow an authenticated att...
CVE-2021-27755MEDIUM5.5"Sametime Android potential path traversal vulnerability when using File class"
CVE-2021-27753MEDIUM5.5"Sametime Android PathTraversal Vulnerability"
CVE-2021-26256MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <=...
CVE-2021-25101MEDIUM4.8The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.94 does not sanitise and escape the POST...
CVE-2021-25100MEDIUM6.1The GiveWP WordPress plugin before 2.17.3 does not escape the s parameter before outputting it back in an attribute in t...
CVE-2021-25099MEDIUM6.1The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back i...
CVE-2021-25060MEDIUM5.4The Five Star Business Profile and Schema WordPress plugin before 2.1.7 does not have any authorisation and CSRF in its ...
CVE-2021-25058MEDIUM5.4The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within ...
CVE-2021-25057MEDIUM5.4The Translation Exchange WordPress plugin through 1.0.14 was vulnerable to Authenticated Stored Cross-Site Scripting (XS...
CVE-2021-25055MEDIUM6.1The FeedWordPress plugin before 2022.0123 is affected by a Reflected Cross-Site Scripting (XSS) within the "visibility" ...
CVE-2021-24921MEDIUM6.1The Advanced Database Cleaner WordPress plugin before 3.0.4 does not sanitise and escape $_GET keys and values before ou...
CVE-2021-46701MEDIUM6.5PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit...
CVE-2021-45081MEDIUM5.9An issue was discovered in Cobbler through 3.3.1. Routines in several files use the HTTP protocol instead of the more se...
CVE-2021-45007MEDIUM6.5Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on...
CVE-2021-46700MEDIUM6.5In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double...
CVE-2021-40841MEDIUM6.5A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now