2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20735 | MEDIUM | 6.1 | 1.1% | Jun 22, 2021 | Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier... |
| CVE-2021-20734 | MEDIUM | 6.1 | 1.0% | Jun 22, 2021 | Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbit... |
| CVE-2021-20733 | MEDIUM | 6.1 | 0.8% | Jun 22, 2021 | Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions fro... |
| CVE-2021-34389 | MEDIUM | 5 | 0.3% | Jun 21, 2021 | Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorre... |
| CVE-2021-34387 | MEDIUM | 6.7 | 0.2% | Jun 21, 2021 | The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where th... |
| CVE-2021-34386 | MEDIUM | 6.7 | 0.2% | Jun 21, 2021 | Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation ca... |
| CVE-2021-32698 | MEDIUM | 4.9 | 0.9% | Jun 21, 2021 | eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET r... |
| CVE-2021-24383 | MEDIUM | 5.4 | 2.3% | Jun 21, 2021 | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the M... |
| CVE-2021-24379 | MEDIUM | 5.3 | 1.0% | Jun 21, 2021 | The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not p... |
| CVE-2021-24378 | MEDIUM | 4.8 | 0.6% | Jun 21, 2021 | The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded v... |
| CVE-2021-24374 | MEDIUM | 5.3 | 1.5% | Jun 21, 2021 | The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image ga... |
| CVE-2021-24373 | MEDIUM | 6.1 | 0.8% | Jun 21, 2021 | The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyvalue... |
| CVE-2021-24372 | MEDIUM | 6.1 | 0.8% | Jun 21, 2021 | The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['RE... |
| CVE-2021-24369 | MEDIUM | 5.4 | 0.6% | Jun 21, 2021 | In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, h... |
| CVE-2021-24367 | MEDIUM | 5.4 | 0.6% | Jun 21, 2021 | The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (X... |
| CVE-2021-24366 | MEDIUM | 5.4 | 1.0% | Jun 21, 2021 | The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and es... |
| CVE-2021-24364 | MEDIUM | 6.1 | 2.0% | Jun 21, 2021 | The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather... |
| CVE-2021-24339 | MEDIUM | 5.4 | 0.8% | Jun 21, 2021 | The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cros... |
| CVE-2021-24338 | MEDIUM | 5.4 | 0.8% | Jun 21, 2021 | The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cros... |
| CVE-2021-32697 | MEDIUM | 5.3 | 1.1% | Jun 21, 2021 | neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form s... |
| CVE-2021-21422 | MEDIUM | 6.1 | 1.6% | Jun 21, 2021 | mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: h... |
| CVE-2021-0521 | MEDIUM | 5.5 | 0.1% | Jun 21, 2021 | In getAllPackages of PackageManagerService, there is a possible information disclosure due to a missing permission check... |
| CVE-2021-0504 | MEDIUM | 6.5 | 0.3% | Jun 21, 2021 | In avrc_pars_browse_rsp of avrc_pars_ct.cc, there is a possible out of bounds read due to a missing bounds check. This c... |
| CVE-2021-29060 | MEDIUM | 5.3 | 3.1% | Jun 21, 2021 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below whic... |
| CVE-2021-28833 | MEDIUM | 6.1 | 0.7% | Jun 21, 2021 | Increments Qiita::Markdown before 0.34.0 allows XSS via a crafted gist link, a different vulnerability than CVE-2021-287... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now