2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24533 | MEDIUM | 4.8 | 0.6% | Aug 23, 2021 | The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege u... |
| CVE-2021-24531 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The Charitable – Donation Plugin WordPress plugin before 1.6.51 is affected by an authenticated stored cross-site script... |
| CVE-2021-24529 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for... |
| CVE-2021-24524 | MEDIUM | 4.8 | 0.6% | Aug 23, 2021 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.12.0 did not escape the Donation Level s... |
| CVE-2021-24506 | HIGH | 8.8 | 1.4% | Aug 23, 2021 | The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape... |
| CVE-2021-24497 | HIGH | 7.2 | 1.3% | Aug 23, 2021 | The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user ... |
| CVE-2021-24486 | MEDIUM | 5.4 | 0.6% | Aug 23, 2021 | The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the ali... |
| CVE-2021-35940 | HIGH | 7.1 | 1.2% | Aug 23, 2021 | An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE... |
| CVE-2021-39291 | HIGH | 8.8 | 1.5% | Aug 23, 2021 | Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, ... |
| CVE-2021-39290 | CRITICAL | 9.8 | 1.5% | Aug 23, 2021 | Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4... |
| CVE-2021-39289 | HIGH | 7.5 | 1.0% | Aug 23, 2021 | Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmwa... |
| CVE-2021-39245 | HIGH | 7.5 | 1.3% | Aug 23, 2021 | Hardcoded .htaccess Credentials for getlogs.cgi exist on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices. This affec... |
| CVE-2021-39244 | HIGH | 8.8 | 3.5% | Aug 23, 2021 | Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xto... |
| CVE-2021-39243 | MEDIUM | 6.5 | 0.5% | Aug 23, 2021 | Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. Th... |
| CVE-2021-38598 | CRITICAL | 9.1 | 1.2% | Aug 23, 2021 | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbrid... |
| CVE-2021-37750 | MEDIUM | 6.5 | 2.2% | Aug 23, 2021 | The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer... |
| CVE-2021-39371 | HIGH | 7.5 | 1.5% | Aug 23, 2021 | An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server ... |
| CVE-2021-39368 | MEDIUM | 6.1 | 0.7% | Aug 23, 2021 | Canon Oce Print Exec Workgroup 1.3.2 allows XSS via the lang parameter. |
| CVE-2021-39367 | MEDIUM | 5.3 | 0.8% | Aug 23, 2021 | Canon Oce Print Exec Workgroup 1.3.2 allows Host header injection. |
| CVE-2021-39365 | MEDIUM | 5.9 | 0.9% | Aug 22, 2021 | In GNOME grilo though 0.3.13, grl-net-wc.c does not enable TLS certificate verification on the SoupSessionAsync objects ... |
| CVE-2021-39362 | MEDIUM | 6.1 | 0.6% | Aug 22, 2021 | An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEAT... |
| CVE-2021-39361 | MEDIUM | 5.9 | 0.6% | Aug 22, 2021 | In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSyn... |
| CVE-2021-39360 | MEDIUM | 5.9 | 0.8% | Aug 22, 2021 | In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync ob... |
| CVE-2021-39359 | MEDIUM | 5.9 | 1.1% | Aug 22, 2021 | In GNOME libgda through 6.0.0, gda-web-provider.c does not enable TLS certificate verification on the SoupSessionSync ob... |
| CVE-2021-39358 | MEDIUM | 5.9 | 0.7% | Aug 22, 2021 | In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now