2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44912 | MEDIUM | 5.4 | 0.5% | Feb 9, 2022 | In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploa... |
| CVE-2021-44911 | MEDIUM | 5.4 | 0.6% | Feb 9, 2022 | XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading th... |
| CVE-2021-3813 | MEDIUM | 6.5 | 1.1% | Feb 9, 2022 | Improper Privilege Management in GitHub repository chatwoot/chatwoot prior to v2.2. |
| CVE-2021-40837 | MEDIUM | 5.3 | 0.6% | Feb 9, 2022 | A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01 was discovered whereby decompr... |
| CVE-2021-45919 | MEDIUM | 5.4 | 0.6% | Feb 8, 2022 | Studio 42 elFinder through 2.1.31 allows XSS via an SVG document. |
| CVE-2021-45329 | MEDIUM | 6.1 | 0.8% | Feb 8, 2022 | Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wi... |
| CVE-2021-45328 | MEDIUM | 6.1 | 1.0% | Feb 8, 2022 | Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. |
| CVE-2021-44957 | MEDIUM | 6.5 | 0.8% | Feb 8, 2022 | Global buffer overflow vulnerability exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23705. Issue is in th... |
| CVE-2021-44956 | MEDIUM | 6.5 | 0.8% | Feb 8, 2022 | Two Heap based buffer overflow vulnerabilities exist in ffjpeg through 01.01.2021. It is similar to CVE-2020-23852. Issu... |
| CVE-2021-44864 | MEDIUM | 6.5 | 10.2% | Feb 8, 2022 | TP-Link WR886N 3.0 1.0.1 Build 150127 Rel.34123n is vulnerable to Buffer Overflow. Authenticated attackers can crash rou... |
| CVE-2021-20877 | MEDIUM | 4.8 | 0.8% | Feb 8, 2022 | Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF... |
| CVE-2021-45281 | MEDIUM | 6.1 | 0.7% | Feb 7, 2022 | QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the us... |
| CVE-2021-3861 | MEDIUM | 6.8 | 0.5% | Feb 7, 2022 | The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer... |
| CVE-2021-25106 | MEDIUM | 5.4 | 0.6% | Feb 7, 2022 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1... |
| CVE-2021-25105 | MEDIUM | 4.8 | 0.6% | Feb 7, 2022 | The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile... |
| CVE-2021-25103 | MEDIUM | 4.7 | 0.7% | Feb 7, 2022 | The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in... |
| CVE-2021-25096 | MEDIUM | 6.5 | 1.0% | Feb 7, 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the... |
| CVE-2021-25084 | MEDIUM | 4.3 | 0.6% | Feb 7, 2022 | The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do n... |
| CVE-2021-25077 | MEDIUM | 6.1 | 0.9% | Feb 7, 2022 | The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before ou... |
| CVE-2021-25029 | MEDIUM | 4.8 | 0.6% | Feb 7, 2022 | The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co... |
| CVE-2021-25004 | MEDIUM | 4.9 | 1.1% | Feb 7, 2022 | The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u... |
| CVE-2021-24993 | MEDIUM | 6.5 | 0.5% | Feb 7, 2022 | The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act... |
| CVE-2021-24947 | MEDIUM | 6.5 | 3.0% | Feb 7, 2022 | The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r... |
| CVE-2021-24928 | MEDIUM | 6.5 | 0.9% | Feb 7, 2022 | The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_or... |
| CVE-2021-24880 | MEDIUM | 5.4 | 0.6% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now