2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44217 | MEDIUM | 6.1 | 1.6% | Jan 18, 2022 | In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of t... |
| CVE-2021-41551 | MEDIUM | 4.9 | 1.3% | Jan 18, 2022 | Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP fi... |
| CVE-2021-38695 | MEDIUM | 5.4 | 0.8% | Jan 18, 2022 | SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in... |
| CVE-2021-42357 | MEDIUM | 6.1 | 2.6% | Jan 17, 2022 | When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to impr... |
| CVE-2021-33040 | MEDIUM | 6.1 | 0.9% | Jan 17, 2022 | managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS. |
| CVE-2021-3862 | MEDIUM | 4.8 | 0.7% | Jan 17, 2022 | icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-25067 | MEDIUM | 5.4 | 1.3% | Jan 17, 2022 | The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb... |
| CVE-2021-25065 | MEDIUM | 5.4 | 1.2% | Jan 17, 2022 | The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed... |
| CVE-2021-25061 | MEDIUM | 5.4 | 0.8% | Jan 17, 2022 | The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-ca... |
| CVE-2021-25046 | MEDIUM | 5.4 | 0.6% | Jan 17, 2022 | The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add... |
| CVE-2021-25037 | MEDIUM | 6.5 | 1.3% | Jan 17, 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov... |
| CVE-2021-25025 | MEDIUM | 4.3 | 0.3% | Jan 17, 2022 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_... |
| CVE-2021-25024 | MEDIUM | 6.1 | 0.8% | Jan 17, 2022 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes... |
| CVE-2021-25005 | MEDIUM | 4.8 | 0.6% | Jan 17, 2022 | The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege... |
| CVE-2021-24909 | MEDIUM | 6.1 | 0.8% | Jan 17, 2022 | The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the include... |
| CVE-2021-24838 | MEDIUM | 6.1 | 2.2% | Jan 17, 2022 | The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to t... |
| CVE-2021-3857 | MEDIUM | 5.4 | 0.6% | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3853 | MEDIUM | 6.1 | 0.6% | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4170 | MEDIUM | 5.4 | 0.8% | Jan 16, 2022 | calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-46171 | MEDIUM | 5.5 | 0.6% | Jan 14, 2022 | Modex v2.11 was discovered to contain a NULL pointer dereference in set_create_id() at xtract.c. |
| CVE-2021-46169 | MEDIUM | 5.5 | 0.7% | Jan 14, 2022 | Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache. |
| CVE-2021-46168 | MEDIUM | 5.5 | 0.6% | Jan 14, 2022 | Spin v6.5.1 was discovered to contain an out-of-bounds write in lex() at spinlex.c. |
| CVE-2021-46195 | MEDIUM | 5.5 | 0.8% | Jan 14, 2022 | GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerab... |
| CVE-2021-46022 | MEDIUM | 5.5 | 1.0% | Jan 14, 2022 | An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentat... |
| CVE-2021-46021 | MEDIUM | 5.5 | 1.0% | Jan 14, 2022 | An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentati... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now