2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24164 | MEDIUM | 4.3 | 0.9% | Apr 5, 2021 | In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri... |
| CVE-2021-24158 | MEDIUM | 6.5 | 0.9% | Apr 5, 2021 | Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f... |
| CVE-2021-24157 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no che... |
| CVE-2021-24156 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inj... |
| CVE-2021-24154 | MEDIUM | 4.9 | 1.1% | Apr 5, 2021 | The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f... |
| CVE-2021-24153 | MEDIUM | 5.4 | 1.1% | Apr 5, 2021 | A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had bui... |
| CVE-2021-24152 | MEDIUM | 6.1 | 0.7% | Apr 5, 2021 | The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting. |
| CVE-2021-30109 | MEDIUM | 6.1 | 1.1% | Apr 5, 2021 | Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads t... |
| CVE-2021-30058 | MEDIUM | 6.1 | 1.0% | Apr 5, 2021 | Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script i... |
| CVE-2021-30057 | MEDIUM | 4.8 | 0.7% | Apr 5, 2021 | A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/re... |
| CVE-2021-30056 | MEDIUM | 5.4 | 0.6% | Apr 5, 2021 | Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web scr... |
| CVE-2021-21533 | MEDIUM | 4.3 | 0.8% | Apr 2, 2021 | Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a den... |
| CVE-2021-21532 | MEDIUM | 6.3 | 0.2% | Apr 2, 2021 | Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be p... |
| CVE-2021-21529 | MEDIUM | 5.5 | 0.2% | Apr 2, 2021 | Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malic... |
| CVE-2021-30074 | MEDIUM | 6.1 | 0.8% | Apr 2, 2021 | docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code... |
| CVE-2021-30126 | MEDIUM | 6.5 | 0.7% | Apr 2, 2021 | Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightm... |
| CVE-2021-30125 | MEDIUM | 6.1 | 0.6% | Apr 2, 2021 | Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376. |
| CVE-2021-28941 | MEDIUM | 5.3 | 1.1% | Apr 2, 2021 | Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a reque... |
| CVE-2021-3374 | MEDIUM | 5.3 | 14.3% | Apr 2, 2021 | Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involvin... |
| CVE-2021-29661 | MEDIUM | 5.4 | 0.6% | Apr 2, 2021 | Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parame... |
| CVE-2021-1879 | MEDIUM | 6.1 | 7.1% | Apr 2, 2021 | This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and i... |
| CVE-2021-1801 | MEDIUM | 6.5 | 1.5% | Apr 2, 2021 | This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security U... |
| CVE-2021-1800 | MEDIUM | 5.5 | 0.6% | Apr 2, 2021 | A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application... |
| CVE-2021-1799 | MEDIUM | 6.5 | 1.8% | Apr 2, 2021 | A port redirection issue was addressed with additional port validation. This issue is fixed in macOS Big Sur 11.2, Secur... |
| CVE-2021-1797 | MEDIUM | 5.5 | 0.3% | Apr 2, 2021 | The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.2, Security Update 2021... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now