2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24509MEDIUM5.4The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing ...
CVE-2021-24507CRITICAL9.8The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t...
CVE-2021-24505MEDIUM5.4The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issue...
CVE-2021-24502MEDIUM4.8The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the p...
CVE-2021-24501HIGH8.1The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user wa...
CVE-2021-24500HIGH8.1Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing...
CVE-2021-24499CRITICAL9.8The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader...
CVE-2021-24495MEDIUM6.1The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter befo...
CVE-2021-24467MEDIUM6.5The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows atta...
CVE-2021-24304MEDIUM6.1The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, lea...
CVE-2021-38209LOW3.3net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net names...
CVE-2021-38208MEDIUM5.5net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NUL...
CVE-2021-38207HIGH7.5drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial...
CVE-2021-38206MEDIUM5.5The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers...
CVE-2021-38205LOW3.3drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat ...
CVE-2021-38204MEDIUM6.8drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial...
CVE-2021-38203MEDIUM5.5btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trig...
CVE-2021-38202HIGH7.5fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-boun...
CVE-2021-38201HIGH7.5net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_ba...
CVE-2021-38200MEDIUM5.5arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specif...
CVE-2021-38199MEDIUM6.5fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of...
CVE-2021-38198MEDIUM5.5arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shado...
CVE-2021-38197CRITICAL9.8unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR arc...
CVE-2021-23419CRITICAL9.8This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying propertie...
CVE-2021-38196CRITICAL9.8An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now