2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4422 | MEDIUM | 4.3 | 0.5% | Jul 12, 2023 | The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2021-4421 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2021-4420 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5.... |
| CVE-2021-4419 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin... |
| CVE-2021-4417 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Reque... |
| CVE-2021-4416 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The wp-mpdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1. Th... |
| CVE-2021-4415 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin... |
| CVE-2021-4414 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ... |
| CVE-2021-4413 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, ... |
| CVE-2021-4412 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. ... |
| CVE-2021-4411 | MEDIUM | 4.3 | 0.4% | Jul 12, 2023 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to... |
| CVE-2021-4410 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2021-4409 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and... |
| CVE-2021-4408 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2021-4407 | MEDIUM | 4.3 | 0.3% | Jul 12, 2023 | The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.... |
| CVE-2021-4406 | HIGH | 7.2 | 0.8% | Jul 10, 2023 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager... |
| CVE-2021-42083 | MEDIUM | 5.4 | 0.5% | Jul 10, 2023 | An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager... |
| CVE-2021-42082 | HIGH | 7.8 | 0.2% | Jul 10, 2023 | Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl ... |
| CVE-2021-42081 | HIGH | 7.2 | 1.0% | Jul 10, 2023 | An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDR... |
| CVE-2021-42080 | HIGH | 7.4 | 0.6% | Jul 10, 2023 | An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDR... |
| CVE-2021-42079 | MEDIUM | 4.9 | 0.6% | Jul 10, 2023 | An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively w... |
| CVE-2021-39014 | MEDIUM | 5.4 | 0.4% | Jul 7, 2023 | IBM Cloud Object System 3.15.8.97 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed... |
| CVE-2021-32495 | CRITICAL | 9.1 | 0.6% | Jul 7, 2023 | Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afte... |
| CVE-2021-32494 | HIGH | 7.5 | 0.7% | Jul 7, 2023 | Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create m... |
| CVE-2021-33798 | MEDIUM | 6.5 | 0.5% | Jul 7, 2023 | A null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now