2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24652 | MEDIUM | 6.5 | 0.7% | Sep 27, 2021 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any ... |
| CVE-2021-24643 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow us... |
| CVE-2021-24634 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properti... |
| CVE-2021-24633 | MEDIUM | 4.3 | 0.7% | Sep 27, 2021 | The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, whi... |
| CVE-2021-24632 | MEDIUM | 6.1 | 0.8% | Sep 27, 2021 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting i... |
| CVE-2021-24610 | MEDIUM | 4.8 | 5.4% | Sep 27, 2021 | The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The... |
| CVE-2021-24569 | MEDIUM | 4.8 | 0.6% | Sep 27, 2021 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Tex... |
| CVE-2021-36878 | MEDIUM | 4.3 | 0.4% | Sep 27, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for a... |
| CVE-2021-26587 | MEDIUM | 6.5 | 0.5% | Sep 27, 2021 | A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerabilit... |
| CVE-2021-37786 | MEDIUM | 4.6 | 0.2% | Sep 27, 2021 | Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper h... |
| CVE-2021-40109 | MEDIUM | 6.4 | 0.5% | Sep 27, 2021 | A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A us... |
| CVE-2021-3818 | MEDIUM | 5.3 | 2.4% | Sep 27, 2021 | grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking |
| CVE-2021-3799 | MEDIUM | 5.4 | 1.5% | Sep 27, 2021 | grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames |
| CVE-2021-40106 | MEDIUM | 6.1 | 0.6% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the webs... |
| CVE-2021-40105 | MEDIUM | 6.1 | 0.6% | Sep 27, 2021 | An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments. |
| CVE-2021-0660 | MEDIUM | 4.9 | 0.5% | Sep 27, 2021 | In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosur... |
| CVE-2021-0425 | MEDIUM | 5.5 | 0.1% | Sep 27, 2021 | In memory management driver, there is a possible side channel information disclosure. This could lead to local informati... |
| CVE-2021-0424 | MEDIUM | 5.5 | 0.1% | Sep 27, 2021 | In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de... |
| CVE-2021-0423 | MEDIUM | 5.5 | 0.1% | Sep 27, 2021 | In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to lo... |
| CVE-2021-0422 | MEDIUM | 5.5 | 0.1% | Sep 27, 2021 | In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de... |
| CVE-2021-0421 | MEDIUM | 5.5 | 0.1% | Sep 27, 2021 | In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead t... |
| CVE-2021-23054 | MEDIUM | 6.1 | 0.6% | Sep 27, 2021 | On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.... |
| CVE-2021-20317 | MEDIUM | 4.4 | 0.4% | Sep 27, 2021 | A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add ... |
| CVE-2021-41580 | MEDIUM | 5.3 | 1.3% | Sep 27, 2021 | The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token... |
| CVE-2021-41385 | MEDIUM | 6.5 | 0.7% | Sep 27, 2021 | The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now