2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36177 | MEDIUM | 4.3 | 0.3% | Feb 2, 2022 | An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x... |
| CVE-2021-38560 | MEDIUM | 6.1 | 2.9% | Feb 1, 2022 | Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in ... |
| CVE-2021-44746 | MEDIUM | 5.3 | 1.1% | Feb 1, 2022 | UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Man... |
| CVE-2021-44451 | MEDIUM | 6.5 | 7.9% | Feb 1, 2022 | Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated us... |
| CVE-2021-46253 | MEDIUM | 5.4 | 0.6% | Feb 1, 2022 | A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute... |
| CVE-2021-45416 | MEDIUM | 6.1 | 3.0% | Feb 1, 2022 | Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the... |
| CVE-2021-43848 | MEDIUM | 5.9 | 2.7% | Feb 1, 2022 | h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory.... |
| CVE-2021-41571 | MEDIUM | 6.5 | 1.8% | Feb 1, 2022 | In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the auth... |
| CVE-2021-25097 | MEDIUM | 6.5 | 0.4% | Feb 1, 2022 | The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publi... |
| CVE-2021-25092 | MEDIUM | 6.5 | 0.5% | Feb 1, 2022 | The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attack... |
| CVE-2021-25091 | MEDIUM | 6.1 | 0.8% | Feb 1, 2022 | The Link Library WordPress plugin before 7.2.9 does not sanitise and escape the settingscopy parameter before outputting... |
| CVE-2021-25089 | MEDIUM | 6.1 | 0.8% | Feb 1, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.16.69 does not sanitise and escape the updraft_restore... |
| CVE-2021-25085 | MEDIUM | 6.1 | 1.7% | Feb 1, 2022 | The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in ... |
| CVE-2021-25072 | MEDIUM | 6.5 | 0.5% | Feb 1, 2022 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when delet... |
| CVE-2021-25063 | MEDIUM | 6.1 | 2.4% | Feb 1, 2022 | The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputt... |
| CVE-2021-24983 | MEDIUM | 6.1 | 1.0% | Feb 1, 2022 | The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not sanitise and escape POSted parameters sen... |
| CVE-2021-24975 | MEDIUM | 6.1 | 1.3% | Feb 1, 2022 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.24 does not sanitise and escape logged requests... |
| CVE-2021-24944 | MEDIUM | 4.8 | 0.6% | Feb 1, 2022 | The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high priv... |
| CVE-2021-24937 | MEDIUM | 6.1 | 0.8% | Feb 1, 2022 | The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area pa... |
| CVE-2021-24934 | MEDIUM | 6.1 | 1.4% | Feb 1, 2022 | The Visual CSS Style Editor WordPress plugin before 7.5.4 does not sanitise and escape the wyp_page_type parameter befor... |
| CVE-2021-24926 | MEDIUM | 6.1 | 12.9% | Feb 1, 2022 | The Domain Check WordPress plugin before 1.0.17 does not sanitise and escape the domain parameter before outputting it b... |
| CVE-2021-24900 | MEDIUM | 4.8 | 0.7% | Feb 1, 2022 | The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow ... |
| CVE-2021-24868 | MEDIUM | 4.3 | 0.9% | Feb 1, 2022 | The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated... |
| CVE-2021-24775 | MEDIUM | 5.3 | 1.3% | Feb 1, 2022 | The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to... |
| CVE-2021-24765 | MEDIUM | 6.1 | 1.4% | Feb 1, 2022 | The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before o... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now