2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24265 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The “Rife Elementor Extensions & Templates” WordPress Plugin before 1.1.6 has a widget that is vulnerable to stored Cros... |
| CVE-2021-24264 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The “Image Hover Effects – Elementor Addon” WordPress Plugin before 1.3.4 has a widget that is vulnerable to stored Cros... |
| CVE-2021-24263 | MEDIUM | 5.4 | 0.7% | May 5, 2021 | The “Elementor Addons – PowerPack Addons for Elementor” WordPress Plugin before 2.3.2 for WordPress has several widgets ... |
| CVE-2021-24262 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The “WooLentor – WooCommerce Elementor Addons + Builder” WordPress Plugin before 1.8.6 has a widget that is vulnerable t... |
| CVE-2021-24261 | MEDIUM | 5.4 | 0.7% | May 5, 2021 | The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vu... |
| CVE-2021-24260 | MEDIUM | 5.4 | 0.7% | May 5, 2021 | The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-... |
| CVE-2021-24259 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The “Elementor Addon Elements” WordPress Plugin before 1.11.2 has several widgets that are vulnerable to stored Cross-Si... |
| CVE-2021-24258 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The Elements Kit Lite and Elements Kit Pro WordPress Plugins before 2.2.0 have a number of widgets that are vulnerable t... |
| CVE-2021-24257 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The “Premium Addons for Elementor” WordPress Plugin before 4.2.8 has several widgets that are vulnerable to stored Cross... |
| CVE-2021-24256 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The “Elementor – Header, Footer & Blocks Template” WordPress Plugin before 1.5.8 has two widgets that are vulnerable to ... |
| CVE-2021-24255 | MEDIUM | 5.4 | 0.6% | May 5, 2021 | The Essential Addons for Elementor Lite WordPress Plugin before 4.5.4 has two widgets that are vulnerable to stored Cros... |
| CVE-2021-29489 | MEDIUM | 5.4 | 0.9% | May 5, 2021 | Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options str... |
| CVE-2021-20397 | MEDIUM | 6.1 | 0.7% | May 5, 2021 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2021-20254 | MEDIUM | 6.8 | 1.6% | May 5, 2021 | A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids... |
| CVE-2021-29250 | MEDIUM | 5.4 | 0.5% | May 5, 2021 | BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products... |
| CVE-2021-29248 | MEDIUM | 5.3 | 0.8% | May 5, 2021 | BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th... |
| CVE-2021-29247 | MEDIUM | 5.3 | 1.2% | May 5, 2021 | BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th... |
| CVE-2021-29246 | MEDIUM | 6.7 | 1.5% | May 5, 2021 | BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achiev... |
| CVE-2021-29245 | MEDIUM | 5.3 | 0.9% | May 5, 2021 | BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key. |
| CVE-2021-25179 | MEDIUM | 6.1 | 1.4% | May 5, 2021 | SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header. |
| CVE-2021-26804 | MEDIUM | 6.5 | 1.2% | May 4, 2021 | Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validatio... |
| CVE-2021-21264 | MEDIUM | 5.2 | 0.3% | May 3, 2021 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 ... |
| CVE-2021-28359 | MEDIUM | 6.1 | 14.4% | May 2, 2021 | The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects... |
| CVE-2021-31935 | MEDIUM | 6.1 | 0.9% | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandl... |
| CVE-2021-31934 | MEDIUM | 6.1 | 0.9% | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now