2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43692MEDIUM6.1youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytprox...
CVE-2021-43695MEDIUM6.1issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the ...
CVE-2021-43697MEDIUM6.1Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file C...
CVE-2021-43696MEDIUM6.1twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will te...
CVE-2021-43698MEDIUM6.1phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the e...
CVE-2021-24927MEDIUM5.4The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup...
CVE-2021-24918MEDIUM5.4The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before s...
CVE-2021-24908MEDIUM6.1The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attr...
CVE-2021-24899MEDIUM4.8The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all...
CVE-2021-24883MEDIUM5.4The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which co...
CVE-2021-24876MEDIUM6.1The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputtin...
CVE-2021-24842MEDIUM5.4The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib...
CVE-2021-24822MEDIUM5.4The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its...
CVE-2021-24811MEDIUM4.8The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high pr...
CVE-2021-24768MEDIUM4.8The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a...
CVE-2021-24751MEDIUM5.4The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribut...
CVE-2021-24749MEDIUM4.3The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, whi...
CVE-2021-24745MEDIUM5.4The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before ...
CVE-2021-21707MEDIUM5.3In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simpl...
CVE-2021-32061MEDIUM5.3S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a Lis...
CVE-2021-4020MEDIUM5.4janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-43785MEDIUM6.1@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for ...
CVE-2021-43776MEDIUM6.1Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a mali...
CVE-2021-40833MEDIUM5.5A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-serv...
CVE-2021-36919MEDIUM5.4Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (version...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now