2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32613 | MEDIUM | 5.5 | 1.2% | May 14, 2021 | In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. |
| CVE-2021-24291 | MEDIUM | 6.1 | 14.4% | May 14, 2021 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cr... |
| CVE-2021-24287 | MEDIUM | 6.1 | 10.4% | May 14, 2021 | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before ... |
| CVE-2021-24286 | MEDIUM | 6.1 | 13.9% | May 14, 2021 | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab paramete... |
| CVE-2021-24285 | CRITICAL | 9.8 | 14.7% | May 14, 2021 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available... |
| CVE-2021-24284 | CRITICAL | 9.8 | 42.1% | May 14, 2021 | The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload... |
| CVE-2021-24283 | MEDIUM | 5.4 | 0.6% | May 14, 2021 | The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, lead... |
| CVE-2021-24282 | MEDIUM | 6.3 | 0.7% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could... |
| CVE-2021-24281 | MEDIUM | 4.3 | 0.7% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could... |
| CVE-2021-24280 | HIGH | 8.8 | 2.0% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could... |
| CVE-2021-24279 | MEDIUM | 6.5 | 0.8% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the... |
| CVE-2021-24278 | HIGH | 7.5 | 7.4% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce ... |
| CVE-2021-24277 | MEDIUM | 5.4 | 0.6% | May 14, 2021 | The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settin... |
| CVE-2021-24195 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer ... |
| CVE-2021-24194 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit F... |
| CVE-2021-24193 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time ... |
| CVE-2021-24192 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plu... |
| CVE-2021-24191 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site... |
| CVE-2021-24190 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Ma... |
| CVE-2021-24189 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptc... |
| CVE-2021-24188 | HIGH | 8.8 | 1.3% | May 14, 2021 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection... |
| CVE-2021-30183 | HIGH | 7.5 | 0.9% | May 14, 2021 | Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when runni... |
| CVE-2021-32051 | HIGH | 7.5 | 2.2% | May 14, 2021 | Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id par... |
| CVE-2021-31922 | HIGH | 7.5 | 1.0% | May 14, 2021 | An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to s... |
| CVE-2021-33026 | CRITICAL | 9.8 | 7.3% | May 13, 2021 | The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now