2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45420 | CRITICAL | 9.8 | 22.1% | Feb 14, 2022 | Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /... |
| CVE-2021-45444 | HIGH | 7.8 | 2.0% | Feb 14, 2022 | In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demon... |
| CVE-2021-44879 | MEDIUM | 5.5 | 1.2% | Feb 14, 2022 | In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a mov... |
| CVE-2021-25115 | MEDIUM | 6.4 | 0.7% | Feb 14, 2022 | The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log co... |
| CVE-2021-25110 | MEDIUM | 4.3 | 0.9% | Feb 14, 2022 | The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user... |
| CVE-2021-25109 | LOW | 2.7 | 0.8% | Feb 14, 2022 | The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high ... |
| CVE-2021-25107 | MEDIUM | 6.1 | 1.5% | Feb 14, 2022 | The Form Store to DB WordPress plugin before 1.1.1 does not sanitise and escape parameter keys before outputting it back... |
| CVE-2021-25050 | MEDIUM | 4.8 | 0.6% | Feb 14, 2022 | The Remove Footer Credit WordPress plugin before 1.0.11 does properly sanitise its settings, allowing high privilege use... |
| CVE-2021-25033 | MEDIUM | 6.1 | 2.7% | Feb 14, 2022 | The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the ... |
| CVE-2021-25018 | MEDIUM | 5.4 | 0.5% | Feb 14, 2022 | The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks in the ppom_settings_p... |
| CVE-2021-25014 | LOW | 3.5 | 0.6% | Feb 14, 2022 | The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings ... |
| CVE-2021-24904 | MEDIUM | 4.8 | 5.1% | Feb 14, 2022 | The Mortgage Calculators WP WordPress plugin before 1.56 does not implement any sanitisation on the color setting of the... |
| CVE-2021-24874 | MEDIUM | 6.1 | 0.8% | Feb 14, 2022 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape t... |
| CVE-2021-24446 | MEDIUM | 5.4 | 0.3% | Feb 14, 2022 | The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which... |
| CVE-2021-4102 | HIGH | 8.8 | 7.8% | Feb 11, 2022 | Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2021-4101 | HIGH | 8.8 | 1.0% | Feb 11, 2022 | Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exp... |
| CVE-2021-4100 | HIGH | 8.8 | 0.7% | Feb 11, 2022 | Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit... |
| CVE-2021-4099 | HIGH | 8.8 | 0.7% | Feb 11, 2022 | Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit h... |
| CVE-2021-4098 | HIGH | 7.4 | 0.6% | Feb 11, 2022 | Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromis... |
| CVE-2021-46366 | HIGH | 8.8 | 0.7% | Feb 11, 2022 | An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerabil... |
| CVE-2021-46365 | HIGH | 7.8 | 1.6% | Feb 11, 2022 | An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via... |
| CVE-2021-46364 | HIGH | 7.8 | 1.5% | Feb 11, 2022 | A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via... |
| CVE-2021-46363 | HIGH | 7.8 | 1.8% | Feb 11, 2022 | An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via c... |
| CVE-2021-46362 | CRITICAL | 9.8 | 4.4% | Feb 11, 2022 | A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.... |
| CVE-2021-46361 | CRITICAL | 9.8 | 2.6% | Feb 11, 2022 | An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and e... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now