2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24308 | MEDIUM | 5.4 | 3.2% | May 24, 2021 | The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management Sys... |
| CVE-2021-24306 | MEDIUM | 5.4 | 0.6% | May 24, 2021 | The Ultimate Member – User Profile, User Registration, Login & Membership Plugin WordPress plugin before 2.1.20 did not ... |
| CVE-2021-24305 | MEDIUM | 6.1 | 1.2% | May 24, 2021 | The Target First WordPress Plugin v2.0, also previously known as Watcheezy, suffers from a critical unauthenticated stor... |
| CVE-2021-24302 | MEDIUM | 5.4 | 0.6% | May 24, 2021 | The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) v... |
| CVE-2021-24301 | MEDIUM | 5.4 | 0.6% | May 24, 2021 | The Hotjar Connecticator WordPress plugin through 1.1.1 is vulnerable to Stored Cross-Site Scripting (XSS) in the 'hotja... |
| CVE-2021-24300 | MEDIUM | 6.1 | 10.6% | May 24, 2021 | The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did n... |
| CVE-2021-24298 | MEDIUM | 6.1 | 3.5% | May 24, 2021 | The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output b... |
| CVE-2021-24297 | MEDIUM | 6.1 | 0.8% | May 24, 2021 | The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX ac... |
| CVE-2021-24296 | MEDIUM | 4.8 | 0.6% | May 24, 2021 | The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege use... |
| CVE-2021-24294 | MEDIUM | 6.1 | 1.2% | May 24, 2021 | The dsgvoaio_write_log AJAX action of the DSGVO All in one for WP WordPress plugin before 4.0 did not sanitise or escape... |
| CVE-2021-21001 | MEDIUM | 6.5 | 1.1% | May 24, 2021 | On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network a... |
| CVE-2021-33496 | MEDIUM | 6.1 | 1.0% | May 24, 2021 | Dutchcoders transfer.sh before 1.2.4 allows XSS via an inline view. |
| CVE-2021-20725 | MEDIUM | 6.1 | 0.8% | May 24, 2021 | Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows ... |
| CVE-2021-20724 | MEDIUM | 6.1 | 0.8% | May 24, 2021 | Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a r... |
| CVE-2021-20723 | MEDIUM | 6.1 | 0.8% | May 24, 2021 | Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed a... |
| CVE-2021-1558 | MEDIUM | 6.7 | 0.3% | May 22, 2021 | Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privilege... |
| CVE-2021-1557 | MEDIUM | 6.7 | 0.3% | May 22, 2021 | Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, local attacker to elevate privilege... |
| CVE-2021-1358 | MEDIUM | 6.1 | 0.8% | May 22, 2021 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t... |
| CVE-2021-1254 | MEDIUM | 4.8 | 0.7% | May 22, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote att... |
| CVE-2021-33513 | MEDIUM | 5.4 | 0.7% | May 21, 2021 | Plone through 5.2.4 allows XSS via the inline_diff methods in Products.CMFDiffTool. |
| CVE-2021-33512 | MEDIUM | 5.4 | 0.7% | May 21, 2021 | Plone through 5.2.4 allows stored XSS attacks (by a Contributor) by uploading an SVG or HTML document. |
| CVE-2021-33510 | MEDIUM | 4.3 | 1.0% | May 21, 2021 | Plone through 5.2.4 allows remote authenticated managers to conduct SSRF attacks via an event ical URL, to read one line... |
| CVE-2021-33508 | MEDIUM | 5.4 | 0.7% | May 21, 2021 | Plone through 5.2.4 allows XSS via a full name that is mishandled during rendering of the ownership tab of a content ite... |
| CVE-2021-33507 | MEDIUM | 6.1 | 0.8% | May 21, 2021 | Zope Products.CMFCore before 2.5.1 and Products.PluggableAuthService before 2.6.2, as used in Plone through 5.2.4 and ot... |
| CVE-2021-29681 | MEDIUM | 5.3 | 0.9% | May 21, 2021 | IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters i... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now