2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40528 | MEDIUM | 5.9 | 1.3% | Sep 6, 2021 | The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two c... |
| CVE-2021-36096 | MEDIUM | 4.9 | 0.4% | Sep 6, 2021 | Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O... |
| CVE-2021-36095 | MEDIUM | 5.3 | 0.9% | Sep 6, 2021 | Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS ... |
| CVE-2021-36094 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OT... |
| CVE-2021-36093 | MEDIUM | 5.3 | 1.1% | Sep 6, 2021 | It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue... |
| CVE-2021-3768 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3767 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | bookstack is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-25737 | MEDIUM | 4.8 | 1.3% | Sep 6, 2021 | A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a ... |
| CVE-2021-25735 | MEDIUM | 6.5 | 5.2% | Sep 6, 2021 | A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook... |
| CVE-2021-24611 | MEDIUM | 5.4 | 0.3% | Sep 6, 2021 | The Keyword Meta WordPress plugin through 3.0 does not sanitise of escape its settings before outputting them back in th... |
| CVE-2021-24603 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The Site Reviews WordPress plugin before 5.13.1 does not sanitise some of its Review Details when adding a review as an ... |
| CVE-2021-24601 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, whi... |
| CVE-2021-24599 | MEDIUM | 6.1 | 0.8% | Sep 6, 2021 | The Email Encoder – Protect Email Addresses WordPress plugin before 2.1.2 has an endpoint that requires no authenticatio... |
| CVE-2021-24591 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The Highlight WordPress plugin before 0.9.3 does not sanitise its CustomCSS setting, allowing high privilege users to pe... |
| CVE-2021-24590 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The Cookie Notice & Consent Banner for GDPR & CCPA Compliance WordPress plugin before 1.7.2 does not properly sanitize i... |
| CVE-2021-24588 | MEDIUM | 6.1 | 0.8% | Sep 6, 2021 | The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerabilit... |
| CVE-2021-24568 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting i... |
| CVE-2021-24517 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of i... |
| CVE-2021-24513 | MEDIUM | 5.4 | 0.6% | Sep 6, 2021 | The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form ... |
| CVE-2021-24435 | MEDIUM | 6.1 | 1.7% | Sep 6, 2021 | The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET par... |
| CVE-2021-23439 | MEDIUM | 6.1 | 0.9% | Sep 5, 2021 | This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name ... |
| CVE-2021-40509 | MEDIUM | 5.4 | 0.9% | Sep 4, 2021 | ViewCommon.java in JForum2 2.7.0 allows XSS via a user signature. |
| CVE-2021-30621 | MEDIUM | 6.5 | 3.3% | Sep 3, 2021 | Chromium: CVE-2021-30621 UI Spoofing in Autofill |
| CVE-2021-30619 | MEDIUM | 6.5 | 3.3% | Sep 3, 2021 | Chromium: CVE-2021-30619 UI Spoofing in Autofill |
| CVE-2021-30617 | MEDIUM | 6.5 | 3.5% | Sep 3, 2021 | Chromium: CVE-2021-30617 Policy bypass in Blink |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now