2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44964 | MEDIUM | 6.3 | 1.0% | Mar 14, 2022 | Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sa... |
| CVE-2021-42171 | HIGH | 7.2 | 2.5% | Mar 14, 2022 | Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-s... |
| CVE-2021-41952 | MEDIUM | 4.8 | 0.5% | Mar 14, 2022 | Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicio... |
| CVE-2021-25026 | MEDIUM | 5.5 | 0.7% | Mar 14, 2022 | The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could... |
| CVE-2021-25007 | CRITICAL | 9.8 | 1.6% | Mar 14, 2022 | The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, le... |
| CVE-2021-25006 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin da... |
| CVE-2021-25003 | CRITICAL | 9.8 | 56.1% | Mar 14, 2022 | The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to w... |
| CVE-2021-24996 | MEDIUM | 6.1 | 0.8% | Mar 14, 2022 | The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter befor... |
| CVE-2021-24995 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, whic... |
| CVE-2021-24982 | MEDIUM | 6.4 | 0.6% | Mar 14, 2022 | The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting... |
| CVE-2021-24966 | MEDIUM | 4.9 | 5.2% | Mar 14, 2022 | The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high p... |
| CVE-2021-24959 | HIGH | 8.8 | 2.2% | Mar 14, 2022 | The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA... |
| CVE-2021-24958 | MEDIUM | 5.4 | 0.6% | Mar 14, 2022 | The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_... |
| CVE-2021-24950 | MEDIUM | 5.4 | 0.5% | Mar 14, 2022 | The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_... |
| CVE-2021-24940 | MEDIUM | 6.1 | 1.5% | Mar 14, 2022 | The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an a... |
| CVE-2021-24897 | MEDIUM | 5.4 | 0.6% | Mar 14, 2022 | The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with cla... |
| CVE-2021-24895 | MEDIUM | 4.8 | 0.6% | Mar 14, 2022 | The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an ... |
| CVE-2021-24692 | MEDIUM | 6.5 | 1.3% | Mar 14, 2022 | The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any... |
| CVE-2021-43954 | MEDIUM | 4.3 | 0.7% | Mar 14, 2022 | The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have ... |
| CVE-2021-46709 | MEDIUM | 6.1 | 0.6% | Mar 13, 2022 | phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number). |
| CVE-2021-45889 | MEDIUM | 5.4 | 0.6% | Mar 13, 2022 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as dem... |
| CVE-2021-45888 | MEDIUM | 4.8 | 0.6% | Mar 13, 2022 | An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of eve... |
| CVE-2021-45887 | CRITICAL | 9.8 | 3.3% | Mar 13, 2022 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for u... |
| CVE-2021-45886 | HIGH | 8.8 | 0.5% | Mar 13, 2022 | An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web appli... |
| CVE-2021-36368 | LOW | 3.7 | 1.7% | Mar 13, 2022 | An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now