2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39420 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and... |
| CVE-2021-40577 | MEDIUM | 5.4 | 1.6% | Nov 8, 2021 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an... |
| CVE-2021-24840 | MEDIUM | 5.3 | 1.1% | Nov 8, 2021 | The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t... |
| CVE-2021-24832 | MEDIUM | 4.3 | 0.4% | Nov 8, 2021 | The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could a... |
| CVE-2021-24816 | MEDIUM | 4.3 | 0.7% | Nov 8, 2021 | The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX ... |
| CVE-2021-24807 | MEDIUM | 5.4 | 1.4% | Nov 8, 2021 | The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting atta... |
| CVE-2021-24806 | MEDIUM | 4.3 | 0.5% | Nov 8, 2021 | The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could a... |
| CVE-2021-24801 | MEDIUM | 4.3 | 0.4% | Nov 8, 2021 | The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX act... |
| CVE-2021-24798 | MEDIUM | 6.1 | 0.8% | Nov 8, 2021 | The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it bac... |
| CVE-2021-24788 | MEDIUM | 6.5 | 0.9% | Nov 8, 2021 | The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are avai... |
| CVE-2021-24783 | MEDIUM | 6.5 | 0.8% | Nov 8, 2021 | The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow user... |
| CVE-2021-24767 | MEDIUM | 6.5 | 0.5% | Nov 8, 2021 | The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF w... |
| CVE-2021-24766 | MEDIUM | 6.5 | 0.5% | Nov 8, 2021 | The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place whe... |
| CVE-2021-24721 | MEDIUM | 6.5 | 0.9% | Nov 8, 2021 | The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed ... |
| CVE-2021-24710 | MEDIUM | 4.8 | 0.7% | Nov 8, 2021 | The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute... |
| CVE-2021-24708 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti... |
| CVE-2021-24706 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of... |
| CVE-2021-24701 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin... |
| CVE-2021-24698 | MEDIUM | 4.3 | 0.7% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb... |
| CVE-2021-24697 | MEDIUM | 6.1 | 0.8% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm... |
| CVE-2021-24674 | MEDIUM | 6.5 | 0.5% | Nov 8, 2021 | The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could a... |
| CVE-2021-24664 | MEDIUM | 4.8 | 2.4% | Nov 8, 2021 | The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_fie... |
| CVE-2021-24646 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh... |
| CVE-2021-24645 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro... |
| CVE-2021-24616 | MEDIUM | 4.8 | 0.7% | Nov 8, 2021 | The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now