2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25264 | MEDIUM | 6.7 | 0.3% | May 17, 2021 | In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administr... |
| CVE-2021-24327 | MEDIUM | 4.8 | 0.6% | May 17, 2021 | The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Red... |
| CVE-2021-24326 | MEDIUM | 5.4 | 0.6% | May 17, 2021 | The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable t... |
| CVE-2021-24325 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflec... |
| CVE-2021-24324 | MEDIUM | 6.5 | 0.6% | May 17, 2021 | The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to m... |
| CVE-2021-24323 | MEDIUM | 4.8 | 0.7% | May 17, 2021 | When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output bac... |
| CVE-2021-24315 | MEDIUM | 4.8 | 0.7% | May 17, 2021 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Back... |
| CVE-2021-24299 | MEDIUM | 6.1 | 5.5% | May 17, 2021 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant ... |
| CVE-2021-24292 | MEDIUM | 5.4 | 0.6% | May 17, 2021 | The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.... |
| CVE-2021-24290 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticat... |
| CVE-2021-24288 | MEDIUM | 6.1 | 1.9% | May 17, 2021 | When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to G... |
| CVE-2021-27342 | MEDIUM | 5.9 | 4.6% | May 17, 2021 | An authentication brute-force protection mechanism bypass in telnetd in D-Link Router model DIR-842 firmware version 3.0... |
| CVE-2021-29052 | MEDIUM | 4.3 | 0.8% | May 17, 2021 | The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permi... |
| CVE-2021-29051 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's Asset Publisher app in Liferay Portal 7.2.1 through 7.3.5... |
| CVE-2021-29048 | MEDIUM | 6.1 | 0.9% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Layout module's page administration page in Liferay Portal 7.3.4, 7.3.5 ... |
| CVE-2021-29046 | MEDIUM | 6.1 | 0.9% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's category selector input field in Liferay Portal 7.3.5 and... |
| CVE-2021-29045 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Redirect module's redirection administration page in Liferay Portal 7.3.... |
| CVE-2021-29044 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | Cross-site scripting (XSS) vulnerability in the Site module's membership request administration pages in Liferay Portal ... |
| CVE-2021-29043 | MEDIUM | 5.9 | 0.8% | May 17, 2021 | The Portal Store module in Liferay Portal 7.0.0 through 7.3.5, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pa... |
| CVE-2021-29041 | MEDIUM | 6.5 | 1.1% | May 16, 2021 | Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 all... |
| CVE-2021-29040 | MEDIUM | 5.3 | 1.1% | May 16, 2021 | The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 2... |
| CVE-2021-29039 | MEDIUM | 6.1 | 0.8% | May 16, 2021 | Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 al... |
| CVE-2021-32054 | MEDIUM | 6.1 | 1.0% | May 14, 2021 | Firely/Incendi Spark before 1.5.5-r4 lacks Content-Disposition headers in certain situations, which may cause crafted fi... |
| CVE-2021-3537 | MEDIUM | 5.9 | 3.5% | May 14, 2021 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixe... |
| CVE-2021-29619 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. Passing invalid arguments (e.g., discovered via f... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now