2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36177MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x...
CVE-2021-38560MEDIUM6.1Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in ...
CVE-2021-44746MEDIUM5.3UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Man...
CVE-2021-44451MEDIUM6.5Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated us...
CVE-2021-46253MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute...
CVE-2021-45416MEDIUM6.1Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the...
CVE-2021-43848MEDIUM5.9h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory....
CVE-2021-41571MEDIUM6.5In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the auth...
CVE-2021-25097MEDIUM6.5The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publi...
CVE-2021-25092MEDIUM6.5The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attack...
CVE-2021-25091MEDIUM6.1The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting...
CVE-2021-25089MEDIUM6.1The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore...
CVE-2021-25085MEDIUM6.1The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in ...
CVE-2021-25072MEDIUM6.5The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when delet...
CVE-2021-25063MEDIUM6.1The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputt...
CVE-2021-24983MEDIUM6.1The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sen...
CVE-2021-24975MEDIUM6.1The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests...
CVE-2021-24944MEDIUM4.8The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high priv...
CVE-2021-24937MEDIUM6.1The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area pa...
CVE-2021-24934MEDIUM6.1The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter befor...
CVE-2021-24926MEDIUM6.1The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it b...
CVE-2021-24900MEDIUM4.8The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow ...
CVE-2021-24868MEDIUM4.3The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated...
CVE-2021-24775MEDIUM5.3The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to...
CVE-2021-24765MEDIUM6.1The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before o...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now