2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24764MEDIUM6.1The Perfect Survey WordPress plugin before 1.5.2 does not sanitise and escape multiple parameters (id and filters[sessio...
CVE-2021-24761MEDIUM6.5The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not ha...
CVE-2021-24707MEDIUM4.8The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, whi...
CVE-2021-24686MEDIUM4.8The SVG Support WordPress plugin before 2.3.20 does not escape the "CSS Class to target" setting before outputting it in...
CVE-2021-24648MEDIUM6.1The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before ...
CVE-2021-46668MEDIUM5.5MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact ...
CVE-2021-46667MEDIUM5.5MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
CVE-2021-46666MEDIUM5.5MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE c...
CVE-2021-46665MEDIUM5.5MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
CVE-2021-46664MEDIUM5.5MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
CVE-2021-46663MEDIUM5.5MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
CVE-2021-46662MEDIUM5.5MariaDB through 10.5.9 allows a set_var.cc application crash via certain uses of an UPDATE statement in conjunction with...
CVE-2021-46661MEDIUM5.5MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common t...
CVE-2021-44114MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows r...
CVE-2021-40042MEDIUM6.5There is a release of invalid pointer vulnerability in some Huawei products, successful exploit may cause the process an...
CVE-2021-40033MEDIUM5.5There is an information exposure vulnerability on several Huawei Products. The vulnerability is due to that the software...
CVE-2021-46659MEDIUM5.5MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to ...
CVE-2021-46658MEDIUM5.5save_window_function_values in MariaDB before 10.6.3 allows an application crash because of incorrect handling of with_w...
CVE-2021-46657MEDIUM5.5get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
CVE-2021-4160MEDIUM5.9There is a carry propagation bug in the MIPS32 and MIPS64 squaring procedure. Many EC algorithms are affected, including...
CVE-2021-46447MEDIUM5.4A cross-site scripting (XSS) vulnerability in H.H.G Multistore v5.1.0 and below allows attackers to execute arbitrary we...
CVE-2021-40415MEDIUM6.5An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC...
CVE-2021-40404MEDIUM6.5An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20...
CVE-2021-40338MEDIUM5.3Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and re...
CVE-2021-31567MEDIUM6.8Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now