2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24609 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before output... |
| CVE-2021-24604 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting... |
| CVE-2021-24600 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them ... |
| CVE-2021-24597 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-S... |
| CVE-2021-24596 | MEDIUM | 4.8 | 2.7% | Sep 20, 2021 | The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin... |
| CVE-2021-24587 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them ... |
| CVE-2021-24585 | MEDIUM | 6.5 | 1.1% | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (... |
| CVE-2021-24584 | MEDIUM | 5.4 | 0.5% | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a times... |
| CVE-2021-24583 | MEDIUM | 4.3 | 1.6% | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a times... |
| CVE-2021-24582 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it i... |
| CVE-2021-24530 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri... |
| CVE-2021-24525 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via sho... |
| CVE-2021-41395 | MEDIUM | 6.5 | 0.8% | Sep 18, 2021 | Teleport before 6.2.12 and 7.x before 7.1.1 allows attackers to control a database connection string, in some situations... |
| CVE-2021-41394 | MEDIUM | 5.3 | 1.2% | Sep 18, 2021 | Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts i... |
| CVE-2021-3806 | MEDIUM | 5.3 | 0.7% | Sep 18, 2021 | A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same netw... |
| CVE-2021-41391 | MEDIUM | 5.4 | 0.6% | Sep 17, 2021 | In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vul... |
| CVE-2021-39218 | MEDIUM | 6.3 | 0.3% | Sep 17, 2021 | Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.26.0 and before version 0.30.0 is ... |
| CVE-2021-41380 | MEDIUM | 6.5 | 0.9% | Sep 17, 2021 | RealVNC Viewer 6.21.406 allows remote VNC servers to cause a denial of service (application crash) via crafted RFB proto... |
| CVE-2021-39219 | MEDIUM | 6.3 | 0.3% | Sep 17, 2021 | Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusio... |
| CVE-2021-39216 | MEDIUM | 6.3 | 0.3% | Sep 17, 2021 | Wasmtime is an open source runtime for WebAssembly & WASI. In Wasmtime from version 0.19.0 and before version 0.30.0 the... |
| CVE-2021-31842 | MEDIUM | 5.5 | 0.2% | Sep 17, 2021 | XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 202... |
| CVE-2021-39327 | MEDIUM | 5.3 | 72.3% | Sep 17, 2021 | The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur... |
| CVE-2021-3812 | MEDIUM | 6.1 | 0.5% | Sep 17, 2021 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3811 | MEDIUM | 6.1 | 0.5% | Sep 17, 2021 | adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-1939 | MEDIUM | 5.5 | 0.1% | Sep 17, 2021 | Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdrag... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now