2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4179 | MEDIUM | 5.4 | 0.5% | Dec 28, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4177 | MEDIUM | 5.3 | 0.9% | Dec 28, 2021 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information |
| CVE-2021-45906 | MEDIUM | 5.4 | 0.5% | Dec 27, 2021 | OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen. |
| CVE-2021-45905 | MEDIUM | 5.4 | 0.5% | Dec 27, 2021 | OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen. |
| CVE-2021-45904 | MEDIUM | 5.4 | 0.5% | Dec 27, 2021 | OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen. |
| CVE-2021-45895 | MEDIUM | 6.1 | 0.7% | Dec 27, 2021 | Netgen Tags Bundle 3.4.x before 3.4.11 and 4.0.x before 4.0.15 allows XSS in the Tags Admin interface. |
| CVE-2021-43552 | MEDIUM | 5.5 | 0.2% | Dec 27, 2021 | The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from t... |
| CVE-2021-43550 | MEDIUM | 6.5 | 0.2% | Dec 27, 2021 | The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive... |
| CVE-2021-43548 | MEDIUM | 6.5 | 0.4% | Dec 27, 2021 | Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrect... |
| CVE-2021-35232 | MEDIUM | 6.1 | 0.3% | Dec 27, 2021 | Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with loca... |
| CVE-2021-43856 | MEDIUM | 5.4 | 0.9% | Dec 27, 2021 | Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through... |
| CVE-2021-43855 | MEDIUM | 5.4 | 0.9% | Dec 27, 2021 | Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through... |
| CVE-2021-38961 | MEDIUM | 6.1 | 0.6% | Dec 27, 2021 | IBM OPENBMC OP910 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c... |
| CVE-2021-24997 | MEDIUM | 6.5 | 2.8% | Dec 27, 2021 | The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any... |
| CVE-2021-24992 | MEDIUM | 4.8 | 0.6% | Dec 27, 2021 | The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before out... |
| CVE-2021-24988 | MEDIUM | 5.4 | 0.3% | Dec 27, 2021 | The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the Syste... |
| CVE-2021-24984 | MEDIUM | 6.1 | 0.8% | Dec 27, 2021 | The WPFront User Role Editor WordPress plugin before 3.2.1.11184 does not sanitise and escape the changes-saved paramete... |
| CVE-2021-24980 | MEDIUM | 6.1 | 0.8% | Dec 27, 2021 | The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter befor... |
| CVE-2021-24979 | MEDIUM | 6.1 | 1.9% | Dec 27, 2021 | The Paid Memberships Pro WordPress plugin before 2.6.6 does not escape the s parameter before outputting it back in an a... |
| CVE-2021-24969 | MEDIUM | 5.4 | 0.6% | Dec 27, 2021 | The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputti... |
| CVE-2021-24967 | MEDIUM | 6.1 | 1.2% | Dec 27, 2021 | The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead valu... |
| CVE-2021-24902 | MEDIUM | 4.8 | 0.6% | Dec 27, 2021 | The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publis... |
| CVE-2021-24797 | MEDIUM | 6.1 | 1.2% | Dec 27, 2021 | The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events befor... |
| CVE-2021-44598 | MEDIUM | 6.1 | 0.7% | Dec 26, 2021 | Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord... |
| CVE-2021-4169 | MEDIUM | 6.1 | 0.9% | Dec 26, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now