2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24130HIGH7.2Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page with...
CVE-2021-24129MEDIUM5.4Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea...
CVE-2021-24128MEDIUM5.4Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross...
CVE-2021-24127MEDIUM5.4Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions...
CVE-2021-24126MEDIUM5.4Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did ...
CVE-2021-24125HIGH7.2Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf...
CVE-2021-24124MEDIUM6.1Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Una...
CVE-2021-24123HIGH7.2Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded fee...
CVE-2021-28133MEDIUM4.3Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the par...
CVE-2021-26237HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user ope...
CVE-2021-26235HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when ...
CVE-2021-26234HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user ope...
CVE-2021-26233HIGH7.8FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when ...
CVE-2021-21627HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to...
CVE-2021-21626MEDIUM4.3Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing fo...
CVE-2021-21625MEDIUM4.3Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTT...
CVE-2021-21624MEDIUM4.3An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with ...
CVE-2021-21623MEDIUM6.5An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with It...
CVE-2021-26236HIGH7.8FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsi...
CVE-2021-23359HIGH8.8This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an at...
CVE-2021-28420MEDIUM4.8A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and th...
CVE-2021-28419HIGH7.2The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads...
CVE-2021-28418MEDIUM4.8A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and ...
CVE-2021-28417MEDIUM4.8A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t...
CVE-2021-3141HIGH7.8In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now