2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22552 | MEDIUM | 5.5 | 0.2% | Aug 2, 2021 | An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall numb... |
| CVE-2021-20332 | MEDIUM | 4.4 | 0.3% | Aug 2, 2021 | Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in... |
| CVE-2021-37216 | MEDIUM | 6.1 | 3.2% | Aug 2, 2021 | QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript w... |
| CVE-2021-34574 | MEDIUM | 4.3 | 0.7% | Aug 2, 2021 | In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 a... |
| CVE-2021-24504 | MEDIUM | 6.1 | 0.8% | Aug 2, 2021 | The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Fi... |
| CVE-2021-24503 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode... |
| CVE-2021-24498 | MEDIUM | 6.1 | 3.1% | Aug 2, 2021 | The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET param... |
| CVE-2021-24496 | MEDIUM | 6.1 | 0.8% | Aug 2, 2021 | The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and success... |
| CVE-2021-24488 | MEDIUM | 6.1 | 11.3% | Aug 2, 2021 | The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not prope... |
| CVE-2021-24481 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an a... |
| CVE-2021-24480 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting ... |
| CVE-2021-24479 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them bac... |
| CVE-2021-24478 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outpu... |
| CVE-2021-24477 | MEDIUM | 6.1 | 0.4% | Aug 2, 2021 | The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a... |
| CVE-2021-24476 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings befor... |
| CVE-2021-24474 | MEDIUM | 6.1 | 0.7% | Aug 2, 2021 | The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refr... |
| CVE-2021-24473 | MEDIUM | 5.4 | 0.8% | Aug 2, 2021 | The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_ima... |
| CVE-2021-24470 | MEDIUM | 5.4 | 0.5% | Aug 2, 2021 | The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, ... |
| CVE-2021-24468 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScri... |
| CVE-2021-24464 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise som... |
| CVE-2021-24455 | MEDIUM | 5.4 | 0.7% | Aug 2, 2021 | The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of A... |
| CVE-2021-24450 | MEDIUM | 4.8 | 0.7% | Aug 2, 2021 | The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin befor... |
| CVE-2021-24448 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Mo... |
| CVE-2021-24444 | MEDIUM | 4.8 | 2.3% | Aug 2, 2021 | The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Tax... |
| CVE-2021-24443 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin be... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now