2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3729 | MEDIUM | 4.3 | 0.4% | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3728 | MEDIUM | 6.5 | 0.5% | Aug 23, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3694 | CRITICAL | 9.6 | 2.4% | Aug 23, 2021 | LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an... |
| CVE-2021-3693 | CRITICAL | 9.6 | 3.0% | Aug 23, 2021 | LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL ... |
| CVE-2021-35465 | LOW | 3.4 | 0.3% | Aug 23, 2021 | Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-s... |
| CVE-2021-33598 | MEDIUM | 6.5 | 0.7% | Aug 23, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component u... |
| CVE-2021-24658 | MEDIUM | 4.8 | 0.7% | Aug 23, 2021 | The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing hi... |
| CVE-2021-24602 | HIGH | 8.8 | 1.5% | Aug 23, 2021 | The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set... |
| CVE-2021-24574 | MEDIUM | 4.8 | 0.7% | Aug 23, 2021 | The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privile... |
| CVE-2021-24571 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when g... |
| CVE-2021-24565 | HIGH | 8.8 | 0.7% | Aug 23, 2021 | The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings,... |
| CVE-2021-24564 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outp... |
| CVE-2021-24562 | HIGH | 7.5 | 1.6% | Aug 23, 2021 | The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 ... |
| CVE-2021-24561 | MEDIUM | 5.4 | 0.7% | Aug 23, 2021 | The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in t... |
| CVE-2021-24558 | MEDIUM | 5.4 | 0.7% | Aug 23, 2021 | The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise,... |
| CVE-2021-24557 | HIGH | 7.2 | 1.5% | Aug 23, 2021 | The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped b... |
| CVE-2021-24556 | MEDIUM | 6.1 | 1.3% | Aug 23, 2021 | The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sani... |
| CVE-2021-24555 | HIGH | 8.8 | 0.8% | Aug 23, 2021 | The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter wh... |
| CVE-2021-24554 | HIGH | 7.2 | 5.7% | Aug 23, 2021 | The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter be... |
| CVE-2021-24553 | HIGH | 7.2 | 1.6% | Aug 23, 2021 | The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before u... |
| CVE-2021-24552 | HIGH | 7.2 | 1.6% | Aug 23, 2021 | The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parame... |
| CVE-2021-24551 | CRITICAL | 9.8 | 1.9% | Aug 23, 2021 | The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter... |
| CVE-2021-24550 | HIGH | 7.2 | 1.6% | Aug 23, 2021 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter befor... |
| CVE-2021-24549 | MEDIUM | 4.9 | 1.6% | Aug 23, 2021 | The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths... |
| CVE-2021-24547 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now