2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24535 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising... |
| CVE-2021-24534 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before out... |
| CVE-2021-24526 | MEDIUM | 5.4 | 1.1% | Aug 16, 2021 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not esca... |
| CVE-2021-24519 | MEDIUM | 4.8 | 0.6% | Aug 16, 2021 | The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' fie... |
| CVE-2021-24518 | MEDIUM | 4.8 | 0.7% | Aug 16, 2021 | The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, all... |
| CVE-2021-24512 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) ... |
| CVE-2021-24471 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, ... |
| CVE-2021-24466 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logg... |
| CVE-2021-24445 | MEDIUM | 5.5 | 0.7% | Aug 16, 2021 | The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit... |
| CVE-2021-24411 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not san... |
| CVE-2021-24410 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, an... |
| CVE-2021-24380 | MEDIUM | 4.3 | 0.4% | Aug 16, 2021 | The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing ... |
| CVE-2021-24363 | MEDIUM | 4.9 | 1.9% | Aug 16, 2021 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded f... |
| CVE-2021-24362 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded S... |
| CVE-2021-35936 | MEDIUM | 5.3 | 4.0% | Aug 16, 2021 | If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor... |
| CVE-2021-3707 | MEDIUM | 5.5 | 1.5% | Aug 16, 2021 | D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification... |
| CVE-2021-38713 | MEDIUM | 5.4 | 0.5% | Aug 16, 2021 | imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header. |
| CVE-2021-38709 | MEDIUM | 6.1 | 0.6% | Aug 16, 2021 | In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for... |
| CVE-2021-38708 | MEDIUM | 5.4 | 0.5% | Aug 16, 2021 | In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS. |
| CVE-2021-26086 | MEDIUM | 5.3 | 100.0% | Aug 16, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr... |
| CVE-2021-38699 | MEDIUM | 5.4 | 8.0% | Aug 15, 2021 | TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs. |
| CVE-2021-37326 | MEDIUM | 5.3 | 0.8% | Aug 15, 2021 | NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations. |
| CVE-2021-36791 | MEDIUM | 5.3 | 0.8% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registrat... |
| CVE-2021-36790 | MEDIUM | 6.1 | 0.6% | Aug 13, 2021 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. |
| CVE-2021-36788 | MEDIUM | 5.4 | 0.5% | Aug 13, 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now