2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24794MEDIUM4.8The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an ...
CVE-2021-24793MEDIUM4.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before ou...
CVE-2021-24789MEDIUM4.8The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute ...
CVE-2021-24781MEDIUM4.3The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrar...
CVE-2021-24773MEDIUM4.8The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputt...
CVE-2021-24770MEDIUM6.5The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX a...
CVE-2021-24757MEDIUM5.3The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a...
CVE-2021-24742MEDIUM6.5The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the ...
CVE-2021-24723MEDIUM5.4The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing us...
CVE-2021-24722MEDIUM4.8The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating...
CVE-2021-24716MEDIUM5.4The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users ...
CVE-2021-24715MEDIUM4.8The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which coul...
CVE-2021-24685MEDIUM5.4The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does...
CVE-2021-24682MEDIUM5.4The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, whi...
CVE-2021-24624MEDIUM4.8The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or es...
CVE-2021-24572MEDIUM4.3The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are ...
CVE-2021-24570MEDIUM4.3The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which inter...
CVE-2021-24539MEDIUM4.8The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or esc...
CVE-2021-41313MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit em...
CVE-2021-20839MEDIUM6.5Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to...
CVE-2021-33259MEDIUM5.3Several web interfaces in D-Link DIR-868LW 1.12b have no authentication requirements for access, allowing for attackers ...
CVE-2021-1123MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can deadlock, which may...
CVE-2021-1122MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL ...
CVE-2021-1121MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource ...
CVE-2021-35237MEDIUM4.3A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacki...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now