2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42009 | MEDIUM | 4.3 | 2.7% | Oct 12, 2021 | An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a speciall... |
| CVE-2021-25738 | MEDIUM | 6.7 | 0.5% | Oct 11, 2021 | Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. |
| CVE-2021-32028 | MEDIUM | 6.5 | 1.4% | Oct 11, 2021 | A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an aut... |
| CVE-2021-22263 | MEDIUM | 6.5 | 1.1% | Oct 11, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.0 before 14.0.9, all versions starting fr... |
| CVE-2021-20121 | MEDIUM | 4 | 0.5% | Oct 11, 2021 | The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file rea... |
| CVE-2021-40541 | MEDIUM | 6.1 | 0.6% | Oct 11, 2021 | PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descri... |
| CVE-2021-40191 | MEDIUM | 5.4 | 0.5% | Oct 11, 2021 | Dzzoffice Version 2.02.1 is affected by cross-site scripting (XSS) due to a lack of sanitization of input data at all up... |
| CVE-2021-40542 | MEDIUM | 6.1 | 3.0% | Oct 11, 2021 | Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute Ja... |
| CVE-2021-29006 | MEDIUM | 6.5 | 7.0% | Oct 11, 2021 | rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any ... |
| CVE-2021-40888 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | Projectsend version r1295 is affected by Cross Site Scripting (XSS) due to lack of sanitization when echo output data in... |
| CVE-2021-40886 | MEDIUM | 6.5 | 1.4% | Oct 11, 2021 | Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2... |
| CVE-2021-24737 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Comments – wpDiscuz WordPress plugin through 7.3.0 does not properly sanitise or escape the Follow and Unfollow mess... |
| CVE-2021-24720 | MEDIUM | 5.4 | 0.9% | Oct 11, 2021 | The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Sc... |
| CVE-2021-24719 | MEDIUM | 6.1 | 3.0% | Oct 11, 2021 | The Enfold Enfold WordPress theme before 4.8.4 was vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability... |
| CVE-2021-24712 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new cal... |
| CVE-2021-24709 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size... |
| CVE-2021-24691 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it ... |
| CVE-2021-24690 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings. |
| CVE-2021-24683 | MEDIUM | 5.4 | 0.4% | Oct 11, 2021 | The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do... |
| CVE-2021-24681 | MEDIUM | 4.8 | 0.9% | Oct 11, 2021 | The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before ... |
| CVE-2021-24656 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp... |
| CVE-2021-24577 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authen... |
| CVE-2021-24576 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordio... |
| CVE-2021-24563 | MEDIUM | 6.1 | 26.4% | Oct 11, 2021 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allow... |
| CVE-2021-24545 | MEDIUM | 5.4 | 1.8% | Oct 11, 2021 | The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now