2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43950MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43952MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default...
CVE-2021-45310MEDIUM5.3Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to ...
CVE-2021-43106MEDIUM6.1A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.3...
CVE-2021-45346MEDIUM4.3A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made...
CVE-2021-39080MEDIUM6.5Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could...
CVE-2021-39079MEDIUM5.4IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This...
CVE-2021-44879MEDIUM5.5In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a mov...
CVE-2021-25115MEDIUM6.4The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log co...
CVE-2021-25110MEDIUM4.3The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user...
CVE-2021-25107MEDIUM6.1The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back...
CVE-2021-25050MEDIUM4.8The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use...
CVE-2021-25033MEDIUM6.1The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the ...
CVE-2021-25018MEDIUM5.4The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_p...
CVE-2021-24904MEDIUM4.8The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the...
CVE-2021-24874MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape t...
CVE-2021-24446MEDIUM5.4The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which...
CVE-2021-4046MEDIUM5.4The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vuln...
CVE-2021-4035MEDIUM4.8A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of ...
CVE-2021-44111MEDIUM4.4A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.
CVE-2021-39688MEDIUM5.5In TBD of TBD, there is a possible out of bounds read due to TBD. This could lead to local information disclosure with n...
CVE-2021-39687MEDIUM5.5In HandleTransactionIoEvent of actuator_driver.cc, there is a possible out of bounds read due to a heap buffer overflow....
CVE-2021-39671MEDIUM6.5In code generated by aidl_const_expressions.cpp, there is a possible out of bounds read due to uninitialized data. This ...
CVE-2021-39666MEDIUM5.5In extract of MediaMetricsItem.h, there is a possible out of bounds read due to improper input validation. This could le...
CVE-2021-39665MEDIUM6.5In checkSpsUpdated of AAVCAssembler.cpp, there is a possible out of bounds read due to a heap buffer overflow. This coul...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now