2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24547 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field. |
| CVE-2021-24533 | MEDIUM | 4.8 | 0.6% | Aug 23, 2021 | The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege u... |
| CVE-2021-24531 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site script... |
| CVE-2021-24529 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for... |
| CVE-2021-24524 | MEDIUM | 4.8 | 0.6% | Aug 23, 2021 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level s... |
| CVE-2021-24486 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the ali... |
| CVE-2021-39243 | MEDIUM | 6.5 | 0.5% | Aug 23, 2021 | Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. Th... |
| CVE-2021-37750 | MEDIUM | 6.5 | 2.2% | Aug 23, 2021 | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer... |
| CVE-2021-39368 | MEDIUM | 6.1 | 0.7% | Aug 23, 2021 | Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter. |
| CVE-2021-39367 | MEDIUM | 5.3 | 0.8% | Aug 23, 2021 | Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection. |
| CVE-2021-39365 | MEDIUM | 5.9 | 0.9% | Aug 22, 2021 | In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects ... |
| CVE-2021-39362 | MEDIUM | 6.1 | 0.6% | Aug 22, 2021 | An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEAT... |
| CVE-2021-39361 | MEDIUM | 5.9 | 0.6% | Aug 22, 2021 | In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSyn... |
| CVE-2021-39360 | MEDIUM | 5.9 | 0.8% | Aug 22, 2021 | In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync ob... |
| CVE-2021-39359 | MEDIUM | 5.9 | 1.1% | Aug 22, 2021 | In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync ob... |
| CVE-2021-39358 | MEDIUM | 5.9 | 0.7% | Aug 22, 2021 | In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync... |
| CVE-2021-36008 | MEDIUM | 5.5 | 2.5% | Aug 20, 2021 | Adobe Illustrator version 25.2.3 (and earlier) is affected by an Use-after-free vulnerability when parsing a specially c... |
| CVE-2021-35985 | MEDIUM | 5.5 | 1.9% | Aug 20, 2021 | Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a... |
| CVE-2021-35984 | MEDIUM | 6.5 | 1.8% | Aug 20, 2021 | Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a... |
| CVE-2021-28593 | MEDIUM | 5.5 | 1.8% | Aug 20, 2021 | Adobe Illustrator version 25.2.3 (and earlier) is affected by a Use After Free vulnerability when parsing a specially cr... |
| CVE-2021-22255 | MEDIUM | 6.5 | 1.3% | Aug 20, 2021 | SSRF in URL file upload in Baserow <1.1.0 allows remote authenticated users to retrieve files from the internal server n... |
| CVE-2021-22254 | MEDIUM | 4.3 | 0.9% | Aug 20, 2021 | Under very specific conditions a user could be impersonated using Gitlab shell. This vulnerability affects GitLab CE/EE ... |
| CVE-2021-22246 | MEDIUM | 6.5 | 1.3% | Aug 20, 2021 | A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abuse... |
| CVE-2021-22238 | MEDIUM | 5.4 | 71.8% | Aug 20, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS ... |
| CVE-2021-34228 | MEDIUM | 6.1 | 29.2% | Aug 20, 2021 | Cross-site scripting in parent_control.htm in TOTOLINK A3002R version V1.1.1-B20200824 (Important Update, new UI) allows... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now