2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24130 | HIGH | 7.2 | 1.4% | Mar 18, 2021 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page with... |
| CVE-2021-24129 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Themify Portfolio Post WordPress plugin, versions before 1.1.6, lea... |
| CVE-2021-24128 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross... |
| CVE-2021-24127 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the ThirstyAffiliates Affiliate Link Manager WordPress plugin, versions... |
| CVE-2021-24126 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did ... |
| CVE-2021-24125 | HIGH | 7.2 | 1.5% | Mar 18, 2021 | Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf... |
| CVE-2021-24124 | MEDIUM | 6.1 | 1.1% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the WP Shieldon WordPress plugin, version 1.6.3 and below, leads to Una... |
| CVE-2021-24123 | HIGH | 7.2 | 1.6% | Mar 18, 2021 | Arbitrary file upload in the PowerPress WordPress plugin, versions before 8.3.8, did not verify some of the uploaded fee... |
| CVE-2021-28133 | MEDIUM | 4.3 | 16.3% | Mar 18, 2021 | Zoom through 5.5.4 sometimes allows attackers to read private information on a participant's screen, even though the par... |
| CVE-2021-26237 | HIGH | 7.8 | 2.7% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d7d, triggered when a user ope... |
| CVE-2021-26235 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when ... |
| CVE-2021-26234 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user ope... |
| CVE-2021-26233 | HIGH | 7.8 | 1.1% | Mar 18, 2021 | FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when ... |
| CVE-2021-21627 | HIGH | 8.8 | 0.8% | Mar 18, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Libvirt Agents Plugin 1.9.0 and earlier allows attackers to... |
| CVE-2021-21626 | MEDIUM | 4.3 | 0.9% | Mar 18, 2021 | Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing fo... |
| CVE-2021-21625 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTT... |
| CVE-2021-21624 | MEDIUM | 4.3 | 0.9% | Mar 18, 2021 | An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with ... |
| CVE-2021-21623 | MEDIUM | 6.5 | 1.0% | Mar 18, 2021 | An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with It... |
| CVE-2021-26236 | HIGH | 7.8 | 2.0% | Mar 18, 2021 | FastStone Image Viewer v.<= 7.5 is affected by a Stack-based Buffer Overflow at 0x005BDF49, affecting the CUR file parsi... |
| CVE-2021-23359 | HIGH | 8.8 | 1.7% | Mar 18, 2021 | This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an at... |
| CVE-2021-28420 | MEDIUM | 4.8 | 1.9% | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via alerts.php and th... |
| CVE-2021-28419 | HIGH | 7.2 | 10.7% | Mar 18, 2021 | The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads... |
| CVE-2021-28418 | MEDIUM | 4.8 | 1.9% | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and ... |
| CVE-2021-28417 | MEDIUM | 4.8 | 1.9% | Mar 18, 2021 | A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and t... |
| CVE-2021-3141 | HIGH | 7.8 | 0.2% | Mar 18, 2021 | In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now