2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24609MEDIUM4.8The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before output...
CVE-2021-24604MEDIUM4.8The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting...
CVE-2021-24600MEDIUM4.8The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them ...
CVE-2021-24597MEDIUM5.4The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-S...
CVE-2021-24596MEDIUM4.8The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin...
CVE-2021-24587MEDIUM5.4The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them ...
CVE-2021-24585MEDIUM6.5The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (...
CVE-2021-24584MEDIUM5.4The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a times...
CVE-2021-24583MEDIUM4.3The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a times...
CVE-2021-24582MEDIUM5.4The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it i...
CVE-2021-24530MEDIUM4.8The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri...
CVE-2021-24525MEDIUM5.4The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via sho...
CVE-2021-41395MEDIUM6.5Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations...
CVE-2021-41394MEDIUM5.3Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts i...
CVE-2021-3806MEDIUM5.3A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same netw...
CVE-2021-41391MEDIUM5.4In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vul...
CVE-2021-39218MEDIUM6.3Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is ...
CVE-2021-41380MEDIUM6.5RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB proto...
CVE-2021-39219MEDIUM6.3Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusio...
CVE-2021-39216MEDIUM6.3Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 the...
CVE-2021-31842MEDIUM5.5XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 202...
CVE-2021-39327MEDIUM5.3The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur...
CVE-2021-3812MEDIUM6.1adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3811MEDIUM6.1adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-1939MEDIUM5.5Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdrag...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now