2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24736 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Word... |
| CVE-2021-24735 | MEDIUM | 6.5 | 0.6% | Oct 18, 2021 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers t... |
| CVE-2021-24734 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could... |
| CVE-2021-24732 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of... |
| CVE-2021-24702 | MEDIUM | 4.8 | 0.7% | Oct 18, 2021 | The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting... |
| CVE-2021-24677 | MEDIUM | 5.3 | 1.2% | Oct 18, 2021 | The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow u... |
| CVE-2021-24675 | MEDIUM | 6.5 | 0.6% | Oct 18, 2021 | The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [av... |
| CVE-2021-24672 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allow... |
| CVE-2021-24642 | MEDIUM | 6.5 | 0.6% | Oct 18, 2021 | The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform an... |
| CVE-2021-24622 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fi... |
| CVE-2021-24617 | MEDIUM | 6.1 | 0.7% | Oct 18, 2021 | The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in mul... |
| CVE-2021-24615 | MEDIUM | 5.4 | 0.4% | Oct 18, 2021 | The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in pl... |
| CVE-2021-24612 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in... |
| CVE-2021-24595 | MEDIUM | 6.5 | 0.5% | Oct 18, 2021 | The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape... |
| CVE-2021-24516 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes... |
| CVE-2021-24416 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its sh... |
| CVE-2021-24415 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate ... |
| CVE-2021-24413 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allow... |
| CVE-2021-24412 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters fro... |
| CVE-2021-22942 | MEDIUM | 6.1 | 1.6% | Oct 18, 2021 | A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow att... |
| CVE-2021-42566 | MEDIUM | 6.1 | 5.8% | Oct 18, 2021 | myfactory.FMS before 7.1-912 allows XSS via the Error parameter. |
| CVE-2021-42565 | MEDIUM | 6.1 | 5.8% | Oct 18, 2021 | myfactory.FMS before 7.1-912 allows XSS via the UID parameter. |
| CVE-2021-36097 | MEDIUM | 4.3 | 0.5% | Oct 18, 2021 | Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the q... |
| CVE-2021-41320 | MEDIUM | 5.5 | 0.2% | Oct 15, 2021 | A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than th... |
| CVE-2021-40995 | MEDIUM | 6.3 | 1.1% | Oct 15, 2021 | A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now