2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24140 | HIGH | 7.2 | 1.2% | Mar 18, 2021 | Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin... |
| CVE-2021-24137 | HIGH | 8.8 | 1.5% | Mar 18, 2021 | Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Post... |
| CVE-2021-24132 | HIGH | 8.8 | 2.6% | Mar 18, 2021 | The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functio... |
| CVE-2021-24131 | HIGH | 7.2 | 1.4% | Mar 18, 2021 | Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated ... |
| CVE-2021-24130 | HIGH | 7.2 | 1.4% | Mar 18, 2021 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page with... |
| CVE-2021-24125 | HIGH | 7.2 | 1.5% | Mar 18, 2021 | Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf... |
| CVE-2021-24123 | HIGH | 7.2 | 1.6% | Mar 18, 2021 | Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded fee... |
| CVE-2021-26237 | HIGH | 7.8 | 2.7% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user ope... |
| CVE-2021-26235 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when ... |
| CVE-2021-26234 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user ope... |
| CVE-2021-26233 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when ... |
| CVE-2021-21627 | HIGH | 8.8 | 0.8% | Mar 18, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to... |
| CVE-2021-26236 | HIGH | 7.8 | 2.0% | Mar 18, 2021 | FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsi... |
| CVE-2021-23359 | HIGH | 8.8 | 1.7% | Mar 18, 2021 | This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an at... |
| CVE-2021-28419 | HIGH | 7.2 | 10.7% | Mar 18, 2021 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads... |
| CVE-2021-3141 | HIGH | 7.8 | 0.2% | Mar 18, 2021 | In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessi... |
| CVE-2021-28667 | HIGH | 7.5 | 2.2% | Mar 18, 2021 | StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. Thi... |
| CVE-2021-20678 | HIGH | 8.8 | 2.0% | Mar 18, 2021 | SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to... |
| CVE-2021-28660 | HIGH | 8.8 | 1.3% | Mar 17, 2021 | rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyo... |
| CVE-2021-27292 | HIGH | 7.5 | 3.4% | Mar 17, 2021 | ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attac... |
| CVE-2021-27291 | HIGH | 7.5 | 3.8% | Mar 17, 2021 | In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. So... |
| CVE-2021-3344 | HIGH | 8.8 | 1.2% | Mar 16, 2021 | A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are... |
| CVE-2021-20218 | HIGH | 7.4 | 1.3% | Mar 16, 2021 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container... |
| CVE-2021-3127 | HIGH | 7.5 | 1.5% | Mar 16, 2021 | NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings ar... |
| CVE-2021-28295 | HIGH | 7.5 | 15.9% | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php,... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now