2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24896 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attri... |
| CVE-2021-24872 | MEDIUM | 6.5 | 1.0% | Dec 13, 2021 | The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other p... |
| CVE-2021-24871 | MEDIUM | 5.4 | 0.7% | Dec 13, 2021 | The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the pa... |
| CVE-2021-24859 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as c... |
| CVE-2021-24855 | MEDIUM | 5.4 | 0.6% | Dec 13, 2021 | The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their conte... |
| CVE-2021-24845 | MEDIUM | 6.5 | 1.0% | Dec 13, 2021 | The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status ... |
| CVE-2021-24836 | MEDIUM | 4.3 | 0.3% | Dec 13, 2021 | The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when upda... |
| CVE-2021-24819 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users... |
| CVE-2021-24818 | MEDIUM | 4.3 | 0.4% | Dec 13, 2021 | The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make ... |
| CVE-2021-24817 | MEDIUM | 5.4 | 0.6% | Dec 13, 2021 | The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, ... |
| CVE-2021-24795 | MEDIUM | 6.5 | 0.5% | Dec 13, 2021 | The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleti... |
| CVE-2021-24792 | MEDIUM | 6.1 | 1.2% | Dec 13, 2021 | The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a templat... |
| CVE-2021-24790 | MEDIUM | 4.3 | 0.4% | Dec 13, 2021 | The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks... |
| CVE-2021-24784 | MEDIUM | 6.5 | 0.5% | Dec 13, 2021 | The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could al... |
| CVE-2021-24782 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could... |
| CVE-2021-24780 | MEDIUM | 4.3 | 0.4% | Dec 13, 2021 | The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could ... |
| CVE-2021-24771 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields whe... |
| CVE-2021-24756 | MEDIUM | 6.1 | 1.3% | Dec 13, 2021 | The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from lo... |
| CVE-2021-24705 | MEDIUM | 4.8 | 0.3% | Dec 13, 2021 | The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape ... |
| CVE-2021-20867 | MEDIUM | 6.5 | 1.4% | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au... |
| CVE-2021-20866 | MEDIUM | 6.5 | 1.7% | Dec 13, 2021 | Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au... |
| CVE-2021-44155 | MEDIUM | 5.3 | 1.8% | Dec 13, 2021 | An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response i... |
| CVE-2021-40858 | MEDIUM | 4.9 | 2.4% | Dec 13, 2021 | Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin pa... |
| CVE-2021-44848 | MEDIUM | 5.3 | 23.1% | Dec 13, 2021 | In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques... |
| CVE-2021-4097 | MEDIUM | 5.4 | 0.8% | Dec 12, 2021 | phpservermon is vulnerable to Improper Neutralization of CRLF Sequences |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now