2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40823 | MEDIUM | 5.9 | 0.6% | Sep 13, 2021 | A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a ... |
| CVE-2021-33366 | MEDIUM | 5.5 | 0.9% | Sep 13, 2021 | Memory leak in the gf_isom_oinf_read_entry function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafte... |
| CVE-2021-33364 | MEDIUM | 5.5 | 0.9% | Sep 13, 2021 | Memory leak in the def_parent_box_new function in MP4Box in GPAC 1.0.1 allows attackers to read memory via a crafted fil... |
| CVE-2021-24725 | MEDIUM | 4.3 | 0.5% | Sep 13, 2021 | The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete co... |
| CVE-2021-24724 | MEDIUM | 5.4 | 0.9% | Sep 13, 2021 | The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, w... |
| CVE-2021-24623 | MEDIUM | 4.8 | 0.6% | Sep 13, 2021 | The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape ... |
| CVE-2021-24621 | MEDIUM | 4.8 | 0.6% | Sep 13, 2021 | The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be ... |
| CVE-2021-24619 | MEDIUM | 4.8 | 0.6% | Sep 13, 2021 | The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing maliciou... |
| CVE-2021-24614 | MEDIUM | 4.8 | 0.6% | Sep 13, 2021 | The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it... |
| CVE-2021-24605 | MEDIUM | 5.4 | 0.6% | Sep 13, 2021 | The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenti... |
| CVE-2021-24586 | MEDIUM | 4.3 | 0.5% | Sep 13, 2021 | The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could a... |
| CVE-2021-24560 | MEDIUM | 6.1 | 0.7% | Sep 13, 2021 | The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before ... |
| CVE-2021-24523 | MEDIUM | 5.4 | 0.6% | Sep 13, 2021 | The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputt... |
| CVE-2021-24510 | MEDIUM | 6.1 | 2.3% | Sep 13, 2021 | The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back... |
| CVE-2021-24508 | MEDIUM | 6.1 | 1.3% | Sep 13, 2021 | The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter ... |
| CVE-2021-24490 | MEDIUM | 6.8 | 0.5% | Sep 13, 2021 | The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import... |
| CVE-2021-24431 | MEDIUM | 4.3 | 0.5% | Sep 13, 2021 | The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did n... |
| CVE-2021-32135 | MEDIUM | 5.5 | 0.8% | Sep 13, 2021 | The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ... |
| CVE-2021-32132 | MEDIUM | 5.5 | 0.8% | Sep 13, 2021 | The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ... |
| CVE-2021-29643 | MEDIUM | 5.4 | 0.6% | Sep 13, 2021 | PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a co... |
| CVE-2021-32137 | MEDIUM | 5.5 | 1.1% | Sep 13, 2021 | Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of s... |
| CVE-2021-32134 | MEDIUM | 5.5 | 0.8% | Sep 13, 2021 | The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via... |
| CVE-2021-40214 | MEDIUM | 5.4 | 0.7% | Sep 13, 2021 | Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component. |
| CVE-2021-22528 | MEDIUM | 5.4 | 0.6% | Sep 13, 2021 | Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
| CVE-2021-22526 | MEDIUM | 6.1 | 0.5% | Sep 13, 2021 | Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4 |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now