2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42833HIGH8.8A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenti...
CVE-2021-25114CRITICAL9.8The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail...
CVE-2021-25108HIGH7.1The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_block...
CVE-2021-25106MEDIUM5.4The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1...
CVE-2021-25105MEDIUM4.8The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile...
CVE-2021-25103MEDIUM4.7The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in...
CVE-2021-25096MEDIUM6.5The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the...
CVE-2021-25095HIGH7.1The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc...
CVE-2021-25084MEDIUM4.3The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do n...
CVE-2021-25077MEDIUM6.1The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before ou...
CVE-2021-25029MEDIUM4.8The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co...
CVE-2021-25004MEDIUM4.9The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u...
CVE-2021-24993MEDIUM6.5The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act...
CVE-2021-24947MEDIUM6.5The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r...
CVE-2021-24928MEDIUM6.5The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_or...
CVE-2021-24880MEDIUM5.4The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which c...
CVE-2021-24879HIGH8.8The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any san...
CVE-2021-24878MEDIUM6.1The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back i...
CVE-2021-24843MEDIUM6.5The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could all...
CVE-2021-24839HIGH7.5The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti...
CVE-2021-46389HIGH7.5IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by ...
CVE-2021-46359HIGH7.5FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successf...
CVE-2021-43929MEDIUM5.4Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work...
CVE-2021-43928HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending...
CVE-2021-43927CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Managemen...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now