2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43692 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytprox... |
| CVE-2021-43695 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the ... |
| CVE-2021-43697 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file C... |
| CVE-2021-43696 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will te... |
| CVE-2021-43698 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the e... |
| CVE-2021-24927 | MEDIUM | 5.4 | 0.6% | Nov 29, 2021 | The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup... |
| CVE-2021-24918 | MEDIUM | 5.4 | 0.7% | Nov 29, 2021 | The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before s... |
| CVE-2021-24908 | MEDIUM | 6.1 | 0.8% | Nov 29, 2021 | The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attr... |
| CVE-2021-24899 | MEDIUM | 4.8 | 0.6% | Nov 29, 2021 | The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all... |
| CVE-2021-24883 | MEDIUM | 5.4 | 0.8% | Nov 29, 2021 | The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which co... |
| CVE-2021-24876 | MEDIUM | 6.1 | 1.2% | Nov 29, 2021 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputtin... |
| CVE-2021-24842 | MEDIUM | 5.4 | 0.7% | Nov 29, 2021 | The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib... |
| CVE-2021-24822 | MEDIUM | 5.4 | 0.3% | Nov 29, 2021 | The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its... |
| CVE-2021-24811 | MEDIUM | 4.8 | 0.6% | Nov 29, 2021 | The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high pr... |
| CVE-2021-24768 | MEDIUM | 4.8 | 0.6% | Nov 29, 2021 | The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a... |
| CVE-2021-24751 | MEDIUM | 5.4 | 0.6% | Nov 29, 2021 | The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribut... |
| CVE-2021-24749 | MEDIUM | 4.3 | 0.4% | Nov 29, 2021 | The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, whi... |
| CVE-2021-24745 | MEDIUM | 5.4 | 0.6% | Nov 29, 2021 | The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before ... |
| CVE-2021-21707 | MEDIUM | 5.3 | 26.0% | Nov 29, 2021 | In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simpl... |
| CVE-2021-32061 | MEDIUM | 5.3 | 1.6% | Nov 29, 2021 | S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a Lis... |
| CVE-2021-4020 | MEDIUM | 5.4 | 0.8% | Nov 27, 2021 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-43785 | MEDIUM | 6.1 | 1.0% | Nov 26, 2021 | @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for ... |
| CVE-2021-43776 | MEDIUM | 6.1 | 0.7% | Nov 26, 2021 | Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a mali... |
| CVE-2021-40833 | MEDIUM | 5.5 | 0.4% | Nov 26, 2021 | A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-serv... |
| CVE-2021-36919 | MEDIUM | 5.4 | 0.5% | Nov 26, 2021 | Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (version... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now