2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24509 | MEDIUM | 5.4 | 0.6% | Aug 9, 2021 | The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing ... |
| CVE-2021-24507 | CRITICAL | 9.8 | 11.3% | Aug 9, 2021 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t... |
| CVE-2021-24505 | MEDIUM | 5.4 | 0.6% | Aug 9, 2021 | The Forms WordPress plugin before 1.12.3 did not sanitise its input fields, leading to Stored Cross-Site scripting issue... |
| CVE-2021-24502 | MEDIUM | 4.8 | 0.7% | Aug 9, 2021 | The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the p... |
| CVE-2021-24501 | HIGH | 8.1 | 1.3% | Aug 9, 2021 | The Workreap WordPress theme before 2.2.2 had several AJAX actions missing authorization checks to verify that a user wa... |
| CVE-2021-24500 | HIGH | 8.1 | 0.6% | Aug 9, 2021 | Several AJAX actions available in the Workreap WordPress theme before 2.2.2 lacked CSRF protections, as well as allowing... |
| CVE-2021-24499 | CRITICAL | 9.8 | 60.4% | Aug 9, 2021 | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader... |
| CVE-2021-24495 | MEDIUM | 6.1 | 2.9% | Aug 9, 2021 | The Marmoset Viewer WordPress plugin before 1.9.3 does not property sanitize, validate or escape the 'id' parameter befo... |
| CVE-2021-24467 | MEDIUM | 6.5 | 0.6% | Aug 9, 2021 | The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows atta... |
| CVE-2021-24304 | MEDIUM | 6.1 | 1.2% | Aug 9, 2021 | The Newsmag WordPress theme before 5.0 does not sanitise the td_block_id parameter in its td_ajax_block AJAX action, lea... |
| CVE-2021-38209 | LOW | 3.3 | 0.3% | Aug 8, 2021 | net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net names... |
| CVE-2021-38208 | MEDIUM | 5.5 | 0.5% | Aug 8, 2021 | net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NUL... |
| CVE-2021-38207 | HIGH | 7.5 | 3.4% | Aug 8, 2021 | drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial... |
| CVE-2021-38206 | MEDIUM | 5.5 | 0.3% | Aug 8, 2021 | The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers... |
| CVE-2021-38205 | LOW | 3.3 | 0.3% | Aug 8, 2021 | drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat ... |
| CVE-2021-38204 | MEDIUM | 6.8 | 0.3% | Aug 8, 2021 | drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial... |
| CVE-2021-38203 | MEDIUM | 5.5 | 0.4% | Aug 8, 2021 | btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trig... |
| CVE-2021-38202 | HIGH | 7.5 | 3.2% | Aug 8, 2021 | fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-boun... |
| CVE-2021-38201 | HIGH | 7.5 | 3.4% | Aug 8, 2021 | net/sunrpc/xdr.c in the Linux kernel before 5.13.4 allows remote attackers to cause a denial of service (xdr_set_page_ba... |
| CVE-2021-38200 | MEDIUM | 5.5 | 0.3% | Aug 8, 2021 | arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specif... |
| CVE-2021-38199 | MEDIUM | 6.5 | 1.2% | Aug 8, 2021 | fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of... |
| CVE-2021-38198 | MEDIUM | 5.5 | 0.5% | Aug 8, 2021 | arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shado... |
| CVE-2021-38197 | CRITICAL | 9.8 | 2.1% | Aug 8, 2021 | unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR arc... |
| CVE-2021-23419 | CRITICAL | 9.8 | 1.1% | Aug 8, 2021 | This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying propertie... |
| CVE-2021-38196 | CRITICAL | 9.8 | 2.6% | Aug 8, 2021 | An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now