2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28145 | MEDIUM | 5.4 | 0.9% | Mar 18, 2021 | Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted su... |
| CVE-2021-26216 | MEDIUM | 4.3 | 0.5% | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php. |
| CVE-2021-26215 | MEDIUM | 4.3 | 0.5% | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php. |
| CVE-2021-24147 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.... |
| CVE-2021-24138 | MEDIUM | 5.5 | 1.2% | Mar 18, 2021 | Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para... |
| CVE-2021-24136 | MEDIUM | 5.4 | 0.8% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t... |
| CVE-2021-24135 | MEDIUM | 6.1 | 1.1% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead t... |
| CVE-2021-24134 | MEDIUM | 4.8 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lea... |
| CVE-2021-24133 | MEDIUM | 4.3 | 0.5% | Mar 18, 2021 | Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could all... |
| CVE-2021-24129 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea... |
| CVE-2021-24128 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross... |
| CVE-2021-24127 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions... |
| CVE-2021-24126 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did ... |
| CVE-2021-24124 | MEDIUM | 6.1 | 1.1% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Una... |
| CVE-2021-28133 | MEDIUM | 4.3 | 16.3% | Mar 18, 2021 | Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the par... |
| CVE-2021-21626 | MEDIUM | 4.3 | 0.9% | Mar 18, 2021 | Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing fo... |
| CVE-2021-21625 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTT... |
| CVE-2021-21624 | MEDIUM | 4.3 | 0.9% | Mar 18, 2021 | An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with ... |
| CVE-2021-21623 | MEDIUM | 6.5 | 1.0% | Mar 18, 2021 | An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with It... |
| CVE-2021-28420 | MEDIUM | 4.8 | 1.9% | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and th... |
| CVE-2021-28418 | MEDIUM | 4.8 | 1.9% | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and ... |
| CVE-2021-28417 | MEDIUM | 4.8 | 1.9% | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t... |
| CVE-2021-28681 | MEDIUM | 5.3 | 0.7% | Mar 18, 2021 | Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerCo... |
| CVE-2021-20676 | MEDIUM | 4.3 | 0.8% | Mar 18, 2021 | M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve... |
| CVE-2021-20675 | MEDIUM | 6.5 | 1.3% | Mar 18, 2021 | M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now