2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4387 | HIGH | 8.8 | 0.5% | Jul 1, 2023 | The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.1... |
| CVE-2021-4386 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2021-4385 | MEDIUM | 4.3 | 0.3% | Jul 1, 2023 | The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2021-4384 | MEDIUM | 4.3 | 0.4% | Jul 1, 2023 | The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions... |
| CVE-2021-42307 | MEDIUM | 4.3 | 1.0% | Jul 1, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2021-34506 | MEDIUM | 6.1 | 2.1% | Jul 1, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2021-34475 | MEDIUM | 5.4 | 0.6% | Jul 1, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-31982 | HIGH | 8.8 | 1.3% | Jul 1, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2021-25828 | MEDIUM | 6.1 | 0.4% | Jun 28, 2023 | Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /... |
| CVE-2021-25827 | CRITICAL | 9.8 | 1.2% | Jun 28, 2023 | Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-addres... |
| CVE-2021-31937 | HIGH | 8.2 | 0.9% | Jun 28, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2021-30205 | MEDIUM | 5.3 | 0.4% | Jun 27, 2023 | Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenti... |
| CVE-2021-30203 | MEDIUM | 6.1 | 0.6% | Jun 27, 2023 | A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers ... |
| CVE-2021-31635 | CRITICAL | 9.8 | 1.0% | Jun 26, 2023 | Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary cod... |
| CVE-2021-0945 | CRITICAL | 9.8 | 0.3% | Jun 15, 2023 | In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via Phy... |
| CVE-2021-0701 | CRITICAL | 9.8 | 0.3% | Jun 15, 2023 | In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer ove... |
| CVE-2021-31280 | MEDIUM | 6.1 | 0.4% | Jun 14, 2023 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter. |
| CVE-2021-46889 | MEDIUM | 6.1 | 0.6% | Jun 7, 2023 | The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other p... |
| CVE-2021-4380 | CRITICAL | 9.8 | 4.5% | Jun 7, 2023 | The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on t... |
| CVE-2021-4379 | MEDIUM | 6.5 | 0.8% | Jun 7, 2023 | The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch... |
| CVE-2021-4337 | HIGH | 8.8 | 1.3% | Jun 7, 2023 | Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability ... |
| CVE-2021-4383 | MEDIUM | 4.3 | 0.8% | Jun 7, 2023 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and includi... |
| CVE-2021-4382 | HIGH | 8.8 | 1.6% | Jun 7, 2023 | The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fet... |
| CVE-2021-4381 | CRITICAL | 9.8 | 1.4% | Jun 7, 2023 | The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, a... |
| CVE-2021-4378 | MEDIUM | 5.4 | 0.5% | Jun 7, 2023 | The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now