2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31852 | MEDIUM | 6.1 | 0.8% | Nov 23, 2021 | A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated a... |
| CVE-2021-31851 | MEDIUM | 6.1 | 0.8% | Nov 23, 2021 | A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated a... |
| CVE-2021-25986 | MEDIUM | 5.4 | 0.6% | Nov 23, 2021 | In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. A... |
| CVE-2021-24894 | MEDIUM | 6.5 | 1.4% | Nov 23, 2021 | The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long inte... |
| CVE-2021-24892 | HIGH | 8.8 | 1.8% | Nov 23, 2021 | Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remot... |
| CVE-2021-24891 | MEDIUM | 6.1 | 24.0% | Nov 23, 2021 | The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM v... |
| CVE-2021-24888 | MEDIUM | 4.8 | 0.7% | Nov 23, 2021 | The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high... |
| CVE-2021-24882 | MEDIUM | 4.8 | 0.6% | Nov 23, 2021 | The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and G... |
| CVE-2021-24877 | HIGH | 7.2 | 1.2% | Nov 23, 2021 | The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a ... |
| CVE-2021-24875 | MEDIUM | 6.1 | 1.6% | Nov 23, 2021 | The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter... |
| CVE-2021-24873 | MEDIUM | 6.1 | 0.8% | Nov 23, 2021 | The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attribute... |
| CVE-2021-24830 | MEDIUM | 4.8 | 0.7% | Nov 23, 2021 | The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, all... |
| CVE-2021-24812 | MEDIUM | 5.4 | 0.6% | Nov 23, 2021 | The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lea... |
| CVE-2021-24729 | MEDIUM | 5.4 | 0.6% | Nov 23, 2021 | The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow... |
| CVE-2021-24713 | MEDIUM | 4.8 | 0.6% | Nov 23, 2021 | The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do n... |
| CVE-2021-24703 | MEDIUM | 5.7 | 0.4% | Nov 23, 2021 | The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate ... |
| CVE-2021-24700 | MEDIUM | 4.8 | 0.6% | Nov 23, 2021 | The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high... |
| CVE-2021-24668 | MEDIUM | 4.3 | 0.4% | Nov 23, 2021 | The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrator... |
| CVE-2021-24644 | HIGH | 7.5 | 5.0% | Nov 23, 2021 | The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the ... |
| CVE-2021-24641 | HIGH | 8.1 | 0.5% | Nov 23, 2021 | The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative ac... |
| CVE-2021-21561 | MEDIUM | 5.5 | 0.2% | Nov 23, 2021 | Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a maliciou... |
| CVE-2021-43019 | HIGH | 7.8 | 2.1% | Nov 23, 2021 | Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources lev... |
| CVE-2021-3672 | MEDIUM | 5.6 | 2.6% | Nov 23, 2021 | A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Se... |
| CVE-2021-37102 | HIGH | 8.8 | 0.9% | Nov 23, 2021 | There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default ce... |
| CVE-2021-37035 | HIGH | 7.5 | 0.7% | Nov 23, 2021 | There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the ap... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now