2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34623 | CRITICAL | 9.8 | 2.1% | Jul 7, 2021 | A vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress Wo... |
| CVE-2021-34622 | HIGH | 8.8 | 4.1% | Jul 7, 2021 | A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfileP... |
| CVE-2021-34621 | CRITICAL | 9.8 | 68.9% | Jul 7, 2021 | A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePr... |
| CVE-2021-34620 | HIGH | 8.8 | 2.6% | Jul 7, 2021 | The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Si... |
| CVE-2021-25952 | CRITICAL | 9.8 | 3.3% | Jul 7, 2021 | Prototype pollution vulnerability in ‘just-safe-set’ versions 1.0.0 through 2.2.1 allows an attacker to cause a denial o... |
| CVE-2021-22555 | HIGH | 7.8 | 78.7% | Jul 7, 2021 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an ... |
| CVE-2021-22225 | MEDIUM | 5.4 | 0.6% | Jul 7, 2021 | Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-... |
| CVE-2021-22224 | MEDIUM | 6.5 | 0.9% | Jul 7, 2021 | A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 ... |
| CVE-2021-26039 | MEDIUM | 6.1 | 0.9% | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to... |
| CVE-2021-26038 | HIGH | 7.5 | 1.2% | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. Install action in com_installer lack the required hardcoded ACL... |
| CVE-2021-26037 | MEDIUM | 5.3 | 1.0% | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions w... |
| CVE-2021-26036 | HIGH | 7.5 | 1.4% | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups t... |
| CVE-2021-26035 | MEDIUM | 6.1 | 0.9% | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads t... |
| CVE-2021-22231 | MEDIUM | 4.3 | 1.0% | Jul 7, 2021 | A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access... |
| CVE-2021-22230 | HIGH | 7.2 | 1.0% | Jul 7, 2021 | Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability a... |
| CVE-2021-22227 | MEDIUM | 6.1 | 0.9% | Jul 7, 2021 | A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to... |
| CVE-2021-20780 | HIGH | 8.8 | 0.9% | Jul 7, 2021 | Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote at... |
| CVE-2021-20779 | HIGH | 8.8 | 0.9% | Jul 7, 2021 | Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.... |
| CVE-2021-20777 | MEDIUM | 4.3 | 0.9% | Jul 7, 2021 | Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2... |
| CVE-2021-20776 | CRITICAL | 9.8 | 1.3% | Jul 7, 2021 | Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction an... |
| CVE-2021-20739 | HIGH | 8.8 | 0.5% | Jul 7, 2021 | WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, a... |
| CVE-2021-20738 | MEDIUM | 6.5 | 0.4% | Jul 7, 2021 | WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain se... |
| CVE-2021-35039 | HIGH | 7.8 | 0.2% | Jul 7, 2021 | kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONF... |
| CVE-2021-22228 | MEDIUM | 6.5 | 1.4% | Jul 6, 2021 | An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13... |
| CVE-2021-22223 | MEDIUM | 6.1 | 0.9% | Jul 6, 2021 | Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted featu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now