2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24527 | CRITICAL | 9.8 | 7.7% | Aug 16, 2021 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to rese... |
| CVE-2021-24526 | MEDIUM | 5.4 | 1.1% | Aug 16, 2021 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not esca... |
| CVE-2021-24519 | MEDIUM | 4.8 | 0.6% | Aug 16, 2021 | The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' fie... |
| CVE-2021-24518 | MEDIUM | 4.8 | 0.7% | Aug 16, 2021 | The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, all... |
| CVE-2021-24512 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) ... |
| CVE-2021-24471 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, ... |
| CVE-2021-24466 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logg... |
| CVE-2021-24445 | MEDIUM | 5.5 | 0.7% | Aug 16, 2021 | The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit... |
| CVE-2021-24411 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not san... |
| CVE-2021-24410 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, an... |
| CVE-2021-24380 | MEDIUM | 4.3 | 0.4% | Aug 16, 2021 | The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing ... |
| CVE-2021-24363 | MEDIUM | 4.9 | 1.9% | Aug 16, 2021 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded f... |
| CVE-2021-24362 | MEDIUM | 6.1 | 0.8% | Aug 16, 2021 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded S... |
| CVE-2021-35936 | MEDIUM | 5.3 | 4.0% | Aug 16, 2021 | If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor... |
| CVE-2021-33193 | HIGH | 7.5 | 46.2% | Aug 16, 2021 | A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request spl... |
| CVE-2021-23423 | HIGH | 7.5 | 1.1% | Aug 16, 2021 | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include... |
| CVE-2021-23422 | HIGH | 7.8 | 0.8% | Aug 16, 2021 | This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Comma... |
| CVE-2021-3708 | HIGH | 7.8 | 24.6% | Aug 16, 2021 | D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticate... |
| CVE-2021-3707 | MEDIUM | 5.5 | 1.5% | Aug 16, 2021 | D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification... |
| CVE-2021-38713 | MEDIUM | 5.4 | 0.5% | Aug 16, 2021 | imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header. |
| CVE-2021-38712 | HIGH | 7.5 | 1.1% | Aug 16, 2021 | OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to bl... |
| CVE-2021-38711 | HIGH | 7.5 | 1.3% | Aug 16, 2021 | In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files. |
| CVE-2021-38709 | MEDIUM | 6.1 | 0.6% | Aug 16, 2021 | In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for... |
| CVE-2021-38708 | MEDIUM | 5.4 | 0.5% | Aug 16, 2021 | In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS. |
| CVE-2021-26086 | MEDIUM | 5.3 | 100.0% | Aug 16, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now