2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44964MEDIUM6.3Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sa...
CVE-2021-42171HIGH7.2Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-s...
CVE-2021-41952MEDIUM4.8Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicio...
CVE-2021-25026MEDIUM5.5The Patreon WordPress plugin before 1.8.2 does not sanitise and escape the field "Custom Patreon Page name", which could...
CVE-2021-25007CRITICAL9.8The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, le...
CVE-2021-25006MEDIUM6.1The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin da...
CVE-2021-25003CRITICAL9.8The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to w...
CVE-2021-24996MEDIUM6.1The IDPay for Contact Form 7 WordPress plugin through 2.1.2 does not sanitise and escape the idpay_error parameter befor...
CVE-2021-24995MEDIUM4.8The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, whic...
CVE-2021-24982MEDIUM6.4The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting...
CVE-2021-24966MEDIUM4.9The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high p...
CVE-2021-24959HIGH8.8The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA...
CVE-2021-24958MEDIUM5.4The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_...
CVE-2021-24950MEDIUM5.4The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_...
CVE-2021-24940MEDIUM6.1The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an a...
CVE-2021-24897MEDIUM5.4The Add Subtitle WordPress plugin through 1.1.0 does not sanitise or escape the sub-title field (available only with cla...
CVE-2021-24895MEDIUM4.8The Cybersoldier WordPress plugin before 1.7.0 does not sanitise and escape the URL settings before outputting it in an ...
CVE-2021-24692MEDIUM6.5The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any...
CVE-2021-43954MEDIUM4.3The DefaultRepositoryAdminService class in Fisheye and Crucible before version 4.8.9 allowed remote attackers, who have ...
CVE-2021-46709MEDIUM6.1phpLiteAdmin through 1.9.8.2 allows XSS via the index.php newRows parameter (aka num or number).
CVE-2021-45889MEDIUM5.4An issue was discovered in PONTON X/P Messenger before 3.11.2. Several functions are vulnerable to reflected XSS, as dem...
CVE-2021-45888MEDIUM4.8An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of eve...
CVE-2021-45887CRITICAL9.8An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for u...
CVE-2021-45886HIGH8.8An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web appli...
CVE-2021-36368LOW3.7An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now