2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33353 | CRITICAL | 9.8 | 2.2% | Mar 8, 2023 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows at... |
| CVE-2021-33352 | CRITICAL | 9.8 | 1.4% | Mar 8, 2023 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitra... |
| CVE-2021-33351 | CRITICAL | 9 | 1.0% | Mar 8, 2023 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allo... |
| CVE-2021-26246 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-23232 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-23224 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-23220 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-23212 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-23199 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-23185 | — | — | — | Mar 7, 2023 | Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021. |
| CVE-2021-4333 | MEDIUM | 6.5 | 0.4% | Mar 7, 2023 | The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.... |
| CVE-2021-4332 | MEDIUM | 6.5 | 0.8% | Mar 7, 2023 | The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin... |
| CVE-2021-4331 | HIGH | 8.8 | 0.9% | Mar 7, 2023 | The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and includin... |
| CVE-2021-4330 | HIGH | 8.8 | 1.5% | Mar 7, 2023 | The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads ... |
| CVE-2021-44197 | MEDIUM | 6.1 | 0.4% | Mar 7, 2023 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo... |
| CVE-2021-44196 | MEDIUM | 6.1 | 0.4% | Mar 7, 2023 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technolo... |
| CVE-2021-36403 | MEDIUM | 5.3 | 0.5% | Mar 6, 2023 | In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidde... |
| CVE-2021-36402 | MEDIUM | 5.3 | 0.5% | Mar 6, 2023 | In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration... |
| CVE-2021-20251 | MEDIUM | 5.9 | 0.8% | Mar 6, 2023 | A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks bei... |
| CVE-2021-36713 | MEDIUM | 6.1 | 0.8% | Mar 6, 2023 | Cross Site Scripting (XSS) vulnerability in the DataTables plug-in 1.9.2 for jQuery allows attackers to run arbitrary co... |
| CVE-2021-36401 | MEDIUM | 4.8 | 0.5% | Mar 6, 2023 | In Moodle, ID numbers exported in HTML data formats required additional sanitizing to prevent a local stored XSS risk. |
| CVE-2021-36400 | MEDIUM | 5.3 | 0.5% | Mar 6, 2023 | In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions. |
| CVE-2021-36399 | MEDIUM | 5.4 | 0.5% | Mar 6, 2023 | In Moodle, ID numbers displayed in the quiz override screens required additional sanitizing to prevent a stored XSS risk... |
| CVE-2021-36398 | MEDIUM | 5.4 | 0.5% | Mar 6, 2023 | In moodle, ID numbers displayed in the web service token list required additional sanitizing to prevent a stored XSS ris... |
| CVE-2021-36397 | MEDIUM | 5.3 | 0.6% | Mar 6, 2023 | In Moodle, insufficient capability checks meant message deletions were not limited to the current user. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now