2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24736MEDIUM4.8The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Word...
CVE-2021-24735MEDIUM6.5The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers t...
CVE-2021-24734MEDIUM5.4The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could...
CVE-2021-24732MEDIUM5.4The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of...
CVE-2021-24702MEDIUM4.8The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting...
CVE-2021-24677MEDIUM5.3The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow u...
CVE-2021-24675MEDIUM6.5The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [av...
CVE-2021-24672MEDIUM5.4The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allow...
CVE-2021-24642MEDIUM6.5The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform an...
CVE-2021-24622MEDIUM4.8The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fi...
CVE-2021-24617MEDIUM6.1The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in mul...
CVE-2021-24615MEDIUM5.4The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in pl...
CVE-2021-24612MEDIUM4.8The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in...
CVE-2021-24595MEDIUM6.5The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape...
CVE-2021-24516MEDIUM4.8The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes...
CVE-2021-24416MEDIUM5.4The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its sh...
CVE-2021-24415MEDIUM5.4The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate ...
CVE-2021-24413MEDIUM5.4The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allow...
CVE-2021-24412MEDIUM5.4The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters fro...
CVE-2021-22942MEDIUM6.1A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow att...
CVE-2021-42566MEDIUM6.1myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
CVE-2021-42565MEDIUM6.1myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
CVE-2021-36097MEDIUM4.3Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the q...
CVE-2021-41320MEDIUM5.5A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than th...
CVE-2021-40995MEDIUM6.3A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now