2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34665 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The WP SEO Tags WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the saq_txt_the_filter parameter in... |
| CVE-2021-34664 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Moova for WooCommerce WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the lat parameter in the ... |
| CVE-2021-34663 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['... |
| CVE-2021-34659 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Plugmatter Pricing Table Lite WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `email` param... |
| CVE-2021-34658 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Simple Popup Newsletter WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER[... |
| CVE-2021-34657 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The 2TypoFR WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the text function found in the ~/vendor... |
| CVE-2021-34656 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scri... |
| CVE-2021-34655 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The WP Songbook WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the url parameter found in the ~/in... |
| CVE-2021-34654 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Custom Post Type Relations WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the cptr[name] param... |
| CVE-2021-34653 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The WP Fountain WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ... |
| CVE-2021-34652 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin... |
| CVE-2021-34651 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Scribble Maps WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the map parameter in the ~/includ... |
| CVE-2021-34649 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Simple Behance Portfolio WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `dark` parameter i... |
| CVE-2021-34644 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_S... |
| CVE-2021-34643 | MEDIUM | 6.1 | 2.4% | Aug 16, 2021 | The Skaut bazar WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] ... |
| CVE-2021-34642 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | The Smart Email Alerts WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the api_key in the ~/views/s... |
| CVE-2021-34641 | MEDIUM | 5.4 | 0.7% | Aug 16, 2021 | The SEOPress WordPress plugin is vulnerable to Stored Cross-Site-Scripting via the processPut function found in the ~/sr... |
| CVE-2021-32825 | CRITICAL | 9.1 | 0.9% | Aug 16, 2021 | bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee438... |
| CVE-2021-32822 | MEDIUM | 5.3 | 1.2% | Aug 16, 2021 | The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable... |
| CVE-2021-22940 | HIGH | 7.5 | 14.0% | Aug 16, 2021 | Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to ... |
| CVE-2021-22939 | MEDIUM | 5.3 | 14.7% | Aug 16, 2021 | If the Node.js https API was used incorrectly and "undefined" was in passed for the "rejectUnauthorized" parameter, no e... |
| CVE-2021-22938 | HIGH | 7.2 | 2.1% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje... |
| CVE-2021-22937 | HIGH | 7.2 | 7.8% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write... |
| CVE-2021-22936 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack a... |
| CVE-2021-22935 | HIGH | 7.2 | 2.1% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now