2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24421 | MEDIUM | 5.4 | 0.6% | Jul 12, 2021 | The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume ... |
| CVE-2021-24420 | MEDIUM | 5.4 | 0.6% | Jul 12, 2021 | The Request a Quote WordPress plugin before 2.3.4 did not sanitise and escape some of its quote fields when adding/editi... |
| CVE-2021-24419 | MEDIUM | 4.8 | 0.6% | Jul 12, 2021 | The WP YouTube Lyte WordPress plugin before 1.7.16 did not sanitise or escape its lyte_yt_api_key and lyte_notification ... |
| CVE-2021-24418 | MEDIUM | 4.8 | 0.6% | Jul 12, 2021 | The Smooth Scroll Page Up/Down Buttons WordPress plugin through 1.4 does not properly sanitise and validate its psb_posi... |
| CVE-2021-24409 | MEDIUM | 6.1 | 1.8% | Jul 12, 2021 | The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attrib... |
| CVE-2021-24408 | MEDIUM | 5.4 | 0.6% | Jul 12, 2021 | The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users... |
| CVE-2021-24385 | CRITICAL | 9.8 | 2.8% | Jul 12, 2021 | The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user inp... |
| CVE-2021-24365 | MEDIUM | 5.4 | 0.9% | Jul 12, 2021 | The Admin Columns WordPress plugin Free before 4.3.2 and Pro before 5.5.2 allowed to configure individual columns for ta... |
| CVE-2021-32707 | MEDIUM | 4.3 | 1.1% | Jul 12, 2021 | Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by defa... |
| CVE-2021-32689 | MEDIUM | 6.5 | 1.0% | Jul 12, 2021 | Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user... |
| CVE-2021-36381 | MEDIUM | 5.3 | 0.9% | Jul 12, 2021 | In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's br... |
| CVE-2021-32705 | HIGH | 7.5 | 1.7% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the... |
| CVE-2021-32703 | MEDIUM | 5.3 | 1.5% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the... |
| CVE-2021-29822 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2021-29805 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-29804 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-29803 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-29794 | HIGH | 7.5 | 0.7% | Jul 12, 2021 | IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expe... |
| CVE-2021-29792 | HIGH | 7.2 | 0.5% | Jul 12, 2021 | IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and ... |
| CVE-2021-23390 | CRITICAL | 9.8 | 2.9% | Jul 12, 2021 | The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. |
| CVE-2021-23389 | CRITICAL | 9.8 | 3.6% | Jul 12, 2021 | The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. |
| CVE-2021-21591 | MEDIUM | 6.7 | 0.2% | Jul 12, 2021 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili... |
| CVE-2021-21590 | MEDIUM | 6.7 | 0.2% | Jul 12, 2021 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili... |
| CVE-2021-21589 | MEDIUM | 6.7 | 0.2% | Jul 12, 2021 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local aut... |
| CVE-2021-21588 | MEDIUM | 4.3 | 0.3% | Jul 12, 2021 | Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An u... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now