2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24652MEDIUM6.5The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any ...
CVE-2021-24643MEDIUM5.4The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow us...
CVE-2021-24634MEDIUM5.4The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properti...
CVE-2021-24633MEDIUM4.3The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, whi...
CVE-2021-24632MEDIUM6.1The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting i...
CVE-2021-24610MEDIUM4.8The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The...
CVE-2021-24569MEDIUM4.8The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Tex...
CVE-2021-36878MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for a...
CVE-2021-26587MEDIUM6.5A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerabilit...
CVE-2021-37786MEDIUM4.6Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper h...
CVE-2021-40109MEDIUM6.4A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A us...
CVE-2021-3818MEDIUM5.3grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
CVE-2021-3799MEDIUM5.4grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
CVE-2021-40106MEDIUM6.1An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the webs...
CVE-2021-40105MEDIUM6.1An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.
CVE-2021-0660MEDIUM4.9In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosur...
CVE-2021-0425MEDIUM5.5In memory management driver, there is a possible side channel information disclosure. This could lead to local informati...
CVE-2021-0424MEDIUM5.5In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de...
CVE-2021-0423MEDIUM5.5In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to lo...
CVE-2021-0422MEDIUM5.5In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de...
CVE-2021-0421MEDIUM5.5In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead t...
CVE-2021-23054MEDIUM6.1On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11....
CVE-2021-20317MEDIUM4.4A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add ...
CVE-2021-41580MEDIUM5.3The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token...
CVE-2021-41385MEDIUM6.5The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now