2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39486 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, pass... |
| CVE-2021-38822 | MEDIUM | 5.4 | 0.7% | Oct 4, 2021 | A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that ... |
| CVE-2021-37331 | MEDIUM | 5.3 | 0.9% | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uplo... |
| CVE-2021-37330 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile... |
| CVE-2021-41878 | MEDIUM | 6.1 | 9.9% | Oct 4, 2021 | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable... |
| CVE-2021-24687 | MEDIUM | 4.8 | 0.6% | Oct 4, 2021 | The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting th... |
| CVE-2021-24679 | MEDIUM | 6.1 | 0.8% | Oct 4, 2021 | The Bitcoin / AltCoin Payment Gateway for WooCommerce WordPress plugin before 1.6.1 does not escape the 's' GET paramete... |
| CVE-2021-24678 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which... |
| CVE-2021-24676 | MEDIUM | 6.1 | 0.8% | Oct 4, 2021 | The Better Find and Replace WordPress plugin before 1.2.9 does not escape the 's' GET parameter before outputting back i... |
| CVE-2021-24673 | MEDIUM | 4.8 | 0.6% | Oct 4, 2021 | The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing... |
| CVE-2021-24654 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url val... |
| CVE-2021-21706 | MEDIUM | 6.5 | 1.3% | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArch... |
| CVE-2021-21705 | MEDIUM | 5.3 | 1.9% | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality vi... |
| CVE-2021-21704 | MEDIUM | 5.9 | 1.7% | Oct 4, 2021 | In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, ... |
| CVE-2021-38109 | MEDIUM | 5.5 | 1.5% | Oct 2, 2021 | Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a crafted file. An un... |
| CVE-2021-38108 | MEDIUM | 5.5 | 1.5% | Oct 2, 2021 | Word97Import200.dll in Corel WordPerfect 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing... |
| CVE-2021-38107 | MEDIUM | 5.5 | 1.5% | Oct 2, 2021 | CdrCore.dll in Corel DrawStandard 2020 22.0.0.474 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
| CVE-2021-38106 | MEDIUM | 5.5 | 1.5% | Oct 1, 2021 | UAX200.dll in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
| CVE-2021-38105 | MEDIUM | 5.5 | 1.5% | Oct 1, 2021 | IPPP82.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
| CVE-2021-38102 | MEDIUM | 5.5 | 1.5% | Oct 1, 2021 | IPPP82.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
| CVE-2021-36309 | MEDIUM | 6.5 | 0.6% | Oct 1, 2021 | Dell Enterprise SONiC OS, versions 3.3.0 and earlier, contains a sensitive information disclosure vulnerability. An auth... |
| CVE-2021-41845 | MEDIUM | 6.5 | 0.7% | Oct 1, 2021 | A SQL injection issue was discovered in ThycoticCentrify Secret Server before 11.0.000007. The only affected versions ar... |
| CVE-2021-38104 | MEDIUM | 5.5 | 1.5% | Oct 1, 2021 | IPPP72.FLT in Corel Presentations 2020 20.0.0.200 is affected by an Out-of-bounds Read vulnerability when parsing a craf... |
| CVE-2021-41467 | MEDIUM | 6.1 | 3.5% | Oct 1, 2021 | Cross-site scripting (XSS) vulnerability in application/controllers/dropbox.php in JustWriting 1.0.0 and below allow rem... |
| CVE-2021-41465 | MEDIUM | 6.1 | 0.8% | Oct 1, 2021 | Cross-site scripting (XSS) vulnerability in concrete/elements/collection_theme.php in concrete5-legacy 5.6.4.0 and below... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now