2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36875MEDIUM4.8Cross-site Scripting (XSS) vulnerability in Stylemix Directory Listings WordPress plugin – uListing allows Reflected XSS...
CVE-2021-36874HIGH8.8Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
CVE-2021-36845MEDIUM4.8Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) ver...
CVE-2021-36841MEDIUM5.4Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1....
CVE-2021-28613HIGH7.4Adobe Creative Cloud Desktop Application version 5.4 (and earlier) is affected by a file handling vulnerability that cou...
CVE-2021-24671MEDIUM5.4The MX Time Zone Clocks WordPress plugin before 3.4.1 does not escape the time_zone attribute of the mxmtzc_time_zone_cl...
CVE-2021-24670MEDIUM5.4The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low...
CVE-2021-24666CRITICAL9.8The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by def...
CVE-2021-24661MEDIUM4.3The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows us...
CVE-2021-24660MEDIUM5.4The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows us...
CVE-2021-24659MEDIUM5.4The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 allows users with a role as low as Contributor...
CVE-2021-24652MEDIUM6.5The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing any ...
CVE-2021-24643MEDIUM5.4The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow us...
CVE-2021-24634MEDIUM5.4The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.3 does not properly sanitise or escape some of the properti...
CVE-2021-24633MEDIUM4.3The Countdown Block WordPress plugin before 1.1.2 does not have authorisation in the eb_write_block_css AJAX action, whi...
CVE-2021-24632MEDIUM6.1The Recipe Card Blocks by WPZOOM WordPress plugin before 2.8.1 does not escape the message parameter before outputting i...
CVE-2021-24610MEDIUM4.8The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The...
CVE-2021-24569MEDIUM4.8The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Tex...
CVE-2021-37539CRITICAL9.8Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
CVE-2021-36878MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for a...
CVE-2021-26587MEDIUM6.5A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerabilit...
CVE-2021-37786MEDIUM4.6Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper h...
CVE-2021-36219CRITICAL9.8An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign...
CVE-2021-36218HIGH7.5An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting ...
CVE-2021-34416CRITICAL9.8The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now