2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36875 | MEDIUM | 4.8 | 0.7% | Sep 27, 2021 | Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS... |
| CVE-2021-36874 | HIGH | 8.8 | 1.1% | Sep 27, 2021 | Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). |
| CVE-2021-36845 | MEDIUM | 4.8 | 0.7% | Sep 27, 2021 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) ver... |
| CVE-2021-36841 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.... |
| CVE-2021-28613 | HIGH | 7.4 | 0.5% | Sep 27, 2021 | Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that cou... |
| CVE-2021-24671 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_cl... |
| CVE-2021-24670 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low... |
| CVE-2021-24666 | CRITICAL | 9.8 | 9.4% | Sep 27, 2021 | The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def... |
| CVE-2021-24661 | MEDIUM | 4.3 | 0.7% | Sep 27, 2021 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows us... |
| CVE-2021-24660 | MEDIUM | 5.4 | 0.5% | Sep 27, 2021 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows us... |
| CVE-2021-24659 | MEDIUM | 5.4 | 0.5% | Sep 27, 2021 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor... |
| CVE-2021-24652 | MEDIUM | 6.5 | 0.7% | Sep 27, 2021 | The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any ... |
| CVE-2021-24643 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow us... |
| CVE-2021-24634 | MEDIUM | 5.4 | 0.6% | Sep 27, 2021 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properti... |
| CVE-2021-24633 | MEDIUM | 4.3 | 0.7% | Sep 27, 2021 | The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, whi... |
| CVE-2021-24632 | MEDIUM | 6.1 | 0.8% | Sep 27, 2021 | The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting i... |
| CVE-2021-24610 | MEDIUM | 4.8 | 5.4% | Sep 27, 2021 | The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The... |
| CVE-2021-24569 | MEDIUM | 4.8 | 0.6% | Sep 27, 2021 | The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Tex... |
| CVE-2021-37539 | CRITICAL | 9.8 | 93.4% | Sep 27, 2021 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. |
| CVE-2021-36878 | MEDIUM | 4.3 | 0.4% | Sep 27, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for a... |
| CVE-2021-26587 | MEDIUM | 6.5 | 0.5% | Sep 27, 2021 | A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerabilit... |
| CVE-2021-37786 | MEDIUM | 4.6 | 0.2% | Sep 27, 2021 | Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper h... |
| CVE-2021-36219 | CRITICAL | 9.8 | 1.6% | Sep 27, 2021 | An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign... |
| CVE-2021-36218 | HIGH | 7.5 | 1.5% | Sep 27, 2021 | An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting ... |
| CVE-2021-34416 | CRITICAL | 9.8 | 1.6% | Sep 27, 2021 | The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now