2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29024 | HIGH | 7.5 | 1.4% | May 17, 2021 | In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and file download. Allowing a... |
| CVE-2021-29023 | MEDIUM | 5.3 | 0.8% | May 17, 2021 | InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mech... |
| CVE-2021-32618 | MEDIUM | 6.1 | 3.3% | May 17, 2021 | The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an i... |
| CVE-2021-32617 | MEDIUM | 5.5 | 1.2% | May 17, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-32456 | MEDIUM | 6.5 | 0.3% | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the au... |
| CVE-2021-32454 | HIGH | 8.8 | 0.4% | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01 makes use of a hardcoded password. An attacker with access to the device could mod... |
| CVE-2021-23384 | MEDIUM | 5.4 | 0.8% | May 17, 2021 | The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slas... |
| CVE-2021-3524 | MEDIUM | 6.5 | 1.6% | May 17, 2021 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability... |
| CVE-2021-33041 | MEDIUM | 6.1 | 1.2% | May 17, 2021 | vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require... |
| CVE-2021-32455 | MEDIUM | 6.5 | 0.4% | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of servi... |
| CVE-2021-32453 | LOW | 3.3 | 0.2% | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network, to access via HTTP to the int... |
| CVE-2021-29747 | HIGH | 7.5 | 1.9% | May 17, 2021 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain highly sensitive information due to a vul... |
| CVE-2021-25264 | MEDIUM | 6.7 | 0.3% | May 17, 2021 | In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administr... |
| CVE-2021-24327 | MEDIUM | 4.8 | 0.6% | May 17, 2021 | The SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 6.4 did not sanitise the Redirect From and Red... |
| CVE-2021-24326 | MEDIUM | 5.4 | 0.6% | May 17, 2021 | The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable t... |
| CVE-2021-24325 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | The tab parameter of the settings page of the 404 SEO Redirection WordPress plugin through 1.3 is vulnerable to a reflec... |
| CVE-2021-24324 | MEDIUM | 6.5 | 0.6% | May 17, 2021 | The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to m... |
| CVE-2021-24323 | MEDIUM | 4.8 | 0.7% | May 17, 2021 | When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output bac... |
| CVE-2021-24315 | MEDIUM | 4.8 | 0.7% | May 17, 2021 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.4 did not sanitise or escape the Back... |
| CVE-2021-24314 | CRITICAL | 9.8 | 1.9% | May 17, 2021 | The Goto WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing pag... |
| CVE-2021-24299 | MEDIUM | 6.1 | 5.5% | May 17, 2021 | The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant ... |
| CVE-2021-24295 | HIGH | 7.5 | 4.7% | May 17, 2021 | It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiS... |
| CVE-2021-24292 | MEDIUM | 5.4 | 0.6% | May 17, 2021 | The Happy Addons for Elementor WordPress plugin before 2.24.0, Happy Addons Pro for Elementor WordPress plugin before 1.... |
| CVE-2021-24290 | MEDIUM | 6.1 | 0.8% | May 17, 2021 | There are several endpoints in the Store Locator Plus for WordPress plugin through 5.5.15 that could allow unauthenticat... |
| CVE-2021-24289 | HIGH | 8.8 | 1.1% | May 17, 2021 | There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authentic... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now