2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25041 | MEDIUM | 6.1 | 0.9% | Dec 6, 2021 | The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues v... |
| CVE-2021-24939 | MEDIUM | 6.1 | 0.8% | Dec 6, 2021 | The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login... |
| CVE-2021-24938 | MEDIUM | 6.1 | 0.8% | Dec 6, 2021 | The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_da... |
| CVE-2021-24935 | MEDIUM | 6.1 | 0.9% | Dec 6, 2021 | The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family pa... |
| CVE-2021-24930 | MEDIUM | 5.4 | 0.6% | Dec 6, 2021 | The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name fi... |
| CVE-2021-24924 | MEDIUM | 6.1 | 0.8% | Dec 6, 2021 | The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in... |
| CVE-2021-24759 | MEDIUM | 5.4 | 0.6% | Dec 6, 2021 | The PDF.js Viewer WordPress plugin before 2.0.2 does not escape some of its shortcode and Gutenberg Block attributes, wh... |
| CVE-2021-24718 | MEDIUM | 4.8 | 0.6% | Dec 6, 2021 | The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its sett... |
| CVE-2021-24714 | MEDIUM | 4.8 | 0.6% | Dec 6, 2021 | The Import any XML or CSV File to WordPress plugin before 3.6.3 does not escape the Import's Title and Unique Identifier... |
| CVE-2021-43043 | MEDIUM | 6.5 | 1.4% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files s... |
| CVE-2021-43039 | MEDIUM | 6.5 | 1.2% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anony... |
| CVE-2021-4005 | MEDIUM | 4.3 | 0.4% | Dec 4, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-35415 | MEDIUM | 4.8 | 0.9% | Dec 3, 2021 | A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte... |
| CVE-2021-38909 | MEDIUM | 5.4 | 0.7% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-29867 | MEDIUM | 5.4 | 0.8% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should ... |
| CVE-2021-29719 | MEDIUM | 5.3 | 1.2% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifyin... |
| CVE-2021-29716 | MEDIUM | 6.5 | 0.9% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user shou... |
| CVE-2021-20493 | MEDIUM | 6.1 | 0.9% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-43991 | MEDIUM | 5.4 | 0.5% | Dec 3, 2021 | The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability ... |
| CVE-2021-43673 | MEDIUM | 6.1 | 0.6% | Dec 3, 2021 | dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of th... |
| CVE-2021-4000 | MEDIUM | 6.1 | 0.8% | Dec 3, 2021 | showdoc is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-44022 | MEDIUM | 5.5 | 0.2% | Dec 3, 2021 | A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected ins... |
| CVE-2021-43772 | MEDIUM | 5.5 | 0.2% | Dec 3, 2021 | Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be ... |
| CVE-2021-25785 | MEDIUM | 4.8 | 0.6% | Dec 2, 2021 | Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management colum... |
| CVE-2021-43327 | MEDIUM | 4.6 | 0.3% | Dec 2, 2021 | An issue was discovered on Renesas RX65 and RX65N devices. With a VCC glitch, an attacker can extract the security ID ke... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now