2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34665MEDIUM6.1The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in...
CVE-2021-34664MEDIUM6.1The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ...
CVE-2021-34663MEDIUM6.1The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['...
CVE-2021-34659MEDIUM6.1The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` param...
CVE-2021-34658MEDIUM6.1The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER[...
CVE-2021-34657MEDIUM6.1The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor...
CVE-2021-34656MEDIUM6.1The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scri...
CVE-2021-34655MEDIUM6.1The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/in...
CVE-2021-34654MEDIUM6.1The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] param...
CVE-2021-34653MEDIUM6.1The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ...
CVE-2021-34652MEDIUM6.1The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin...
CVE-2021-34651MEDIUM6.1The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includ...
CVE-2021-34649MEDIUM6.1The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter i...
CVE-2021-34644MEDIUM6.1The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_S...
CVE-2021-34643MEDIUM6.1The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ...
CVE-2021-34642MEDIUM6.1The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/s...
CVE-2021-34641MEDIUM5.4The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/sr...
CVE-2021-32825CRITICAL9.1bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee438...
CVE-2021-32822MEDIUM5.3The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable...
CVE-2021-22940HIGH7.5Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to ...
CVE-2021-22939MEDIUM5.3If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no e...
CVE-2021-22938HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje...
CVE-2021-22937HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write...
CVE-2021-22936MEDIUM6.1A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack a...
CVE-2021-22935HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now