2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33040MEDIUM6.1managers/views/iframe.js in FuturePress EPub.js before 0.3.89 allows XSS.
CVE-2021-3862MEDIUM4.8icecoder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4164HIGH8.8calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-25067MEDIUM5.4The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb...
CVE-2021-25065MEDIUM5.4The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed...
CVE-2021-25061MEDIUM5.4The WP Booking System WordPress plugin before 2.0.15 was affected by a reflected xss in wp-booking-system on the wpbs-ca...
CVE-2021-25046MEDIUM5.4The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add...
CVE-2021-25037MEDIUM6.5The All in One SEO WordPress plugin before 4.1.5.3 is affected by an authenticated SQL injection issue, which was discov...
CVE-2021-25036HIGH8.8The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur...
CVE-2021-25025MEDIUM4.3The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_...
CVE-2021-25024MEDIUM6.1The EventCalendar WordPress plugin before 1.1.51 does not escape some user input before outputting it back in attributes...
CVE-2021-25005MEDIUM4.8The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege...
CVE-2021-24909MEDIUM6.1The ACF Photo Gallery Field WordPress plugin before 1.7.5 does not sanitise and escape the post parameter in the include...
CVE-2021-24838MEDIUM6.1The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to t...
CVE-2021-3857MEDIUM5.4chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3853MEDIUM6.1chaskiq is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4171CRITICAL9.8calibre-web is vulnerable to Business Logic Errors
CVE-2021-4170MEDIUM5.4calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-44537HIGH7.8ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t...
CVE-2021-33828HIGH8.8The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th...
CVE-2021-33827HIGH7.2The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
CVE-2021-42555HIGH7.5Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validat...
CVE-2021-35969HIGH7.5Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validatio...
CVE-2021-33499HIGH7.5Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).
CVE-2021-33498HIGH7.5Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now