2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24711 | HIGH | 8.8 | 0.7% | Oct 11, 2021 | The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CS... |
| CVE-2021-24709 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size... |
| CVE-2021-24691 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it ... |
| CVE-2021-24690 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings. |
| CVE-2021-24683 | MEDIUM | 5.4 | 0.4% | Oct 11, 2021 | The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do... |
| CVE-2021-24681 | MEDIUM | 4.8 | 0.9% | Oct 11, 2021 | The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before ... |
| CVE-2021-24656 | MEDIUM | 4.8 | 0.6% | Oct 11, 2021 | The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp... |
| CVE-2021-24651 | HIGH | 7.5 | 1.6% | Oct 11, 2021 | The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_po... |
| CVE-2021-24577 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authen... |
| CVE-2021-24576 | MEDIUM | 5.4 | 0.6% | Oct 11, 2021 | The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordio... |
| CVE-2021-24563 | MEDIUM | 6.1 | 26.4% | Oct 11, 2021 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allow... |
| CVE-2021-24546 | HIGH | 8.8 | 1.8% | Oct 11, 2021 | The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Condit... |
| CVE-2021-24545 | MEDIUM | 5.4 | 1.8% | Oct 11, 2021 | The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing t... |
| CVE-2021-40889 | CRITICAL | 9.8 | 1.8% | Oct 11, 2021 | CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php fi... |
| CVE-2021-35060 | MEDIUM | 5.3 | 0.8% | Oct 11, 2021 | /way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response difference... |
| CVE-2021-35059 | MEDIUM | 6.1 | 0.6% | Oct 11, 2021 | OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter. |
| CVE-2021-41832 | HIGH | 7.5 | 1.3% | Oct 11, 2021 | It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apach... |
| CVE-2021-41831 | MEDIUM | 5.3 | 1.5% | Oct 11, 2021 | It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to ... |
| CVE-2021-41830 | HIGH | 7.5 | 1.3% | Oct 11, 2021 | It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All ve... |
| CVE-2021-41801 | HIGH | 8.8 | 1.1% | Oct 11, 2021 | The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitti... |
| CVE-2021-41800 | MEDIUM | 5.3 | 1.7% | Oct 11, 2021 | MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visi... |
| CVE-2021-41799 | HIGH | 7.5 | 1.6% | Oct 11, 2021 | MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQ... |
| CVE-2021-41798 | MEDIUM | 6.1 | 1.3% | Oct 11, 2021 | MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Se... |
| CVE-2021-42139 | CRITICAL | 9.8 | 2.0% | Oct 11, 2021 | Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations. |
| CVE-2021-42137 | MEDIUM | 5.3 | 0.8% | Oct 11, 2021 | An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requiremen... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now