2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33040 | MEDIUM | 6.1 | 0.9% | Jan 17, 2022 | managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS. |
| CVE-2021-3862 | MEDIUM | 4.8 | 0.7% | Jan 17, 2022 | icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4164 | HIGH | 8.8 | 0.5% | Jan 17, 2022 | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-25067 | MEDIUM | 5.4 | 1.3% | Jan 17, 2022 | The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb... |
| CVE-2021-25065 | MEDIUM | 5.4 | 1.2% | Jan 17, 2022 | The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed... |
| CVE-2021-25061 | MEDIUM | 5.4 | 0.8% | Jan 17, 2022 | The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-ca... |
| CVE-2021-25046 | MEDIUM | 5.4 | 0.6% | Jan 17, 2022 | The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add... |
| CVE-2021-25037 | MEDIUM | 6.5 | 1.3% | Jan 17, 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov... |
| CVE-2021-25036 | HIGH | 8.8 | 3.0% | Jan 17, 2022 | The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur... |
| CVE-2021-25025 | MEDIUM | 4.3 | 0.3% | Jan 17, 2022 | The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_... |
| CVE-2021-25024 | MEDIUM | 6.1 | 0.8% | Jan 17, 2022 | The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes... |
| CVE-2021-25005 | MEDIUM | 4.8 | 0.6% | Jan 17, 2022 | The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege... |
| CVE-2021-24909 | MEDIUM | 6.1 | 0.8% | Jan 17, 2022 | The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the include... |
| CVE-2021-24838 | MEDIUM | 6.1 | 2.2% | Jan 17, 2022 | The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to t... |
| CVE-2021-3857 | MEDIUM | 5.4 | 0.6% | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3853 | MEDIUM | 6.1 | 0.6% | Jan 17, 2022 | chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4171 | CRITICAL | 9.8 | 1.4% | Jan 17, 2022 | calibre-web is vulnerable to Business Logic Errors |
| CVE-2021-4170 | MEDIUM | 5.4 | 0.8% | Jan 16, 2022 | calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-44537 | HIGH | 7.8 | 2.7% | Jan 15, 2022 | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t... |
| CVE-2021-33828 | HIGH | 8.8 | 1.2% | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th... |
| CVE-2021-33827 | HIGH | 7.2 | 2.1% | Jan 15, 2022 | The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. |
| CVE-2021-42555 | HIGH | 7.5 | 1.2% | Jan 15, 2022 | Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validat... |
| CVE-2021-35969 | HIGH | 7.5 | 1.2% | Jan 15, 2022 | Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validatio... |
| CVE-2021-33499 | HIGH | 7.5 | 1.2% | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2). |
| CVE-2021-33498 | HIGH | 7.5 | 1.2% | Jan 15, 2022 | Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2). |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now