2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34654 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] param... |
| CVE-2021-34653 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ... |
| CVE-2021-34652 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin... |
| CVE-2021-34651 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includ... |
| CVE-2021-34649 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter i... |
| CVE-2021-34644 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_S... |
| CVE-2021-34643 | MEDIUM | 6.1 | 2.4% | Aug 16, 2021 | The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ... |
| CVE-2021-34642 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/s... |
| CVE-2021-34641 | MEDIUM | 5.4 | 0.7% | Aug 16, 2021 | The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/sr... |
| CVE-2021-32822 | MEDIUM | 5.3 | 1.2% | Aug 16, 2021 | The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable... |
| CVE-2021-22939 | MEDIUM | 5.3 | 14.7% | Aug 16, 2021 | If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no e... |
| CVE-2021-22936 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack a... |
| CVE-2021-22933 | MEDIUM | 6.5 | 1.4% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary... |
| CVE-2021-0114 | MEDIUM | 6.7 | 0.3% | Aug 16, 2021 | Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an... |
| CVE-2021-38757 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. |
| CVE-2021-38756 | MEDIUM | 6.1 | 0.7% | Aug 16, 2021 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php. |
| CVE-2021-38755 | MEDIUM | 5.3 | 1.0% | Aug 16, 2021 | Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php. |
| CVE-2021-38752 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an a... |
| CVE-2021-38751 | MEDIUM | 4.3 | 2.5% | Aug 16, 2021 | A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha... |
| CVE-2021-38607 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input. |
| CVE-2021-24548 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in t... |
| CVE-2021-24541 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which cou... |
| CVE-2021-24540 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which... |
| CVE-2021-24538 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or B... |
| CVE-2021-24536 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now