2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-34654MEDIUM6.1The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] param...
CVE-2021-34653MEDIUM6.1The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ...
CVE-2021-34652MEDIUM6.1The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin...
CVE-2021-34651MEDIUM6.1The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includ...
CVE-2021-34649MEDIUM6.1The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter i...
CVE-2021-34644MEDIUM6.1The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_S...
CVE-2021-34643MEDIUM6.1The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ...
CVE-2021-34642MEDIUM6.1The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/s...
CVE-2021-34641MEDIUM5.4The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/sr...
CVE-2021-32822MEDIUM5.3The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable...
CVE-2021-22939MEDIUM5.3If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no e...
CVE-2021-22936MEDIUM6.1A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack a...
CVE-2021-22933MEDIUM6.5A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary...
CVE-2021-0114MEDIUM6.7Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an...
CVE-2021-38757MEDIUM6.1Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
CVE-2021-38756MEDIUM6.1Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
CVE-2021-38755MEDIUM5.3Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
CVE-2021-38752MEDIUM5.4A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an a...
CVE-2021-38751MEDIUM4.3A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha...
CVE-2021-38607MEDIUM5.4Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
CVE-2021-24548MEDIUM5.4The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in t...
CVE-2021-24541MEDIUM5.4The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which cou...
CVE-2021-24540MEDIUM5.4The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which...
CVE-2021-24538MEDIUM5.4The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or B...
CVE-2021-24536MEDIUM6.1The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now