2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31643 | MEDIUM | 5.4 | 88.4% | Jun 1, 2021 | An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and... |
| CVE-2021-31642 | MEDIUM | 6.5 | 43.7% | Jun 1, 2021 | A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including B... |
| CVE-2021-31641 | MEDIUM | 6.1 | 5.1% | Jun 1, 2021 | An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-... |
| CVE-2021-3543 | MEDIUM | 6.7 | 0.3% | Jun 1, 2021 | A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closur... |
| CVE-2021-3515 | MEDIUM | 6.7 | 0.5% | Jun 1, 2021 | A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB priv... |
| CVE-2021-33182 | MEDIUM | 4.3 | 1.1% | Jun 1, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in ... |
| CVE-2021-25640 | MEDIUM | 6.1 | 2.1% | Jun 1, 2021 | In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which... |
| CVE-2021-24335 | MEDIUM | 6.1 | 3.9% | Jun 1, 2021 | The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey sear... |
| CVE-2021-24334 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise i... |
| CVE-2021-24333 | MEDIUM | 6.5 | 0.8% | Jun 1, 2021 | The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its se... |
| CVE-2021-24331 | MEDIUM | 4.8 | 0.7% | Jun 1, 2021 | The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, ... |
| CVE-2021-24330 | MEDIUM | 4.8 | 0.7% | Jun 1, 2021 | The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not saniti... |
| CVE-2021-24329 | MEDIUM | 5.4 | 3.3% | Jun 1, 2021 | The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settin... |
| CVE-2021-24328 | MEDIUM | 6.2 | 0.6% | Jun 1, 2021 | The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any... |
| CVE-2021-24322 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output ... |
| CVE-2021-24320 | MEDIUM | 6.1 | 10.8% | Jun 1, 2021 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view,... |
| CVE-2021-24319 | MEDIUM | 5.4 | 1.7% | Jun 1, 2021 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before... |
| CVE-2021-24318 | MEDIUM | 6.5 | 1.0% | Jun 1, 2021 | The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki... |
| CVE-2021-24317 | MEDIUM | 6.1 | 0.9% | Jun 1, 2021 | The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation a... |
| CVE-2021-24316 | MEDIUM | 6.1 | 6.4% | Jun 1, 2021 | The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter bef... |
| CVE-2021-24313 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them ... |
| CVE-2021-24310 | MEDIUM | 4.8 | 1.1% | Jun 1, 2021 | The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the ... |
| CVE-2021-24309 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize... |
| CVE-2021-23388 | MEDIUM | 5.3 | 1.7% | Jun 1, 2021 | The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDo... |
| CVE-2021-20585 | MEDIUM | 5.3 | 1.0% | Jun 1, 2021 | IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in furth... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now