2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39995 | MEDIUM | 6.5 | 0.6% | Nov 29, 2021 | Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi c... |
| CVE-2021-43693 | CRITICAL | 9.8 | 1.2% | Nov 29, 2021 | vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php. |
| CVE-2021-43692 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytprox... |
| CVE-2021-43695 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the ... |
| CVE-2021-43697 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file C... |
| CVE-2021-43696 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will te... |
| CVE-2021-43698 | MEDIUM | 6.1 | 0.6% | Nov 29, 2021 | phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the e... |
| CVE-2021-24927 | MEDIUM | 5.4 | 0.6% | Nov 29, 2021 | The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup... |
| CVE-2021-24918 | MEDIUM | 5.4 | 0.7% | Nov 29, 2021 | The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before s... |
| CVE-2021-24915 | CRITICAL | 9.8 | 12.7% | Nov 29, 2021 | The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the... |
| CVE-2021-24908 | MEDIUM | 6.1 | 0.8% | Nov 29, 2021 | The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attr... |
| CVE-2021-24899 | MEDIUM | 4.8 | 0.6% | Nov 29, 2021 | The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all... |
| CVE-2021-24889 | HIGH | 7.2 | 1.3% | Nov 29, 2021 | The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which coul... |
| CVE-2021-24883 | MEDIUM | 5.4 | 0.8% | Nov 29, 2021 | The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which co... |
| CVE-2021-24876 | MEDIUM | 6.1 | 1.2% | Nov 29, 2021 | The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputtin... |
| CVE-2021-24860 | HIGH | 7.2 | 1.3% | Nov 29, 2021 | The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before u... |
| CVE-2021-24842 | MEDIUM | 5.4 | 0.7% | Nov 29, 2021 | The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib... |
| CVE-2021-24822 | MEDIUM | 5.4 | 0.3% | Nov 29, 2021 | The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its... |
| CVE-2021-24811 | MEDIUM | 4.8 | 0.6% | Nov 29, 2021 | The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high pr... |
| CVE-2021-24768 | MEDIUM | 4.8 | 0.6% | Nov 29, 2021 | The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a... |
| CVE-2021-24755 | HIGH | 8.8 | 1.3% | Nov 29, 2021 | The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL stateme... |
| CVE-2021-24751 | MEDIUM | 5.4 | 0.6% | Nov 29, 2021 | The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribut... |
| CVE-2021-24749 | MEDIUM | 4.3 | 0.4% | Nov 29, 2021 | The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, whi... |
| CVE-2021-24748 | HIGH | 8.8 | 1.3% | Nov 29, 2021 | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET pa... |
| CVE-2021-24745 | MEDIUM | 5.4 | 0.6% | Nov 29, 2021 | The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now