2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-44912MEDIUM5.4In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploa...
CVE-2021-44911MEDIUM5.4XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading th...
CVE-2021-3813MEDIUM6.5Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2.
CVE-2021-40837MEDIUM5.3A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompr...
CVE-2021-45919MEDIUM5.4Studio 42 elFinder through 2.1.31 allows XSS via an SVG document.
CVE-2021-45329MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wi...
CVE-2021-45328MEDIUM6.1Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
CVE-2021-44957MEDIUM6.5Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in th...
CVE-2021-44956MEDIUM6.5Two Heap based buffer overflow vulnerabilities exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23852. Issu...
CVE-2021-44864MEDIUM6.5TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash rou...
CVE-2021-20877MEDIUM4.8Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF...
CVE-2021-45281MEDIUM6.1QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the us...
CVE-2021-3861MEDIUM6.8The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer...
CVE-2021-25106MEDIUM5.4The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1...
CVE-2021-25105MEDIUM4.8The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile...
CVE-2021-25103MEDIUM4.7The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in...
CVE-2021-25096MEDIUM6.5The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the...
CVE-2021-25084MEDIUM4.3The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do n...
CVE-2021-25077MEDIUM6.1The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before ou...
CVE-2021-25029MEDIUM4.8The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co...
CVE-2021-25004MEDIUM4.9The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u...
CVE-2021-24993MEDIUM6.5The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act...
CVE-2021-24947MEDIUM6.5The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r...
CVE-2021-24928MEDIUM6.5The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_or...
CVE-2021-24880MEDIUM5.4The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now