2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42833 | HIGH | 8.8 | 0.2% | Feb 7, 2022 | A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenti... |
| CVE-2021-25114 | CRITICAL | 9.8 | 82.2% | Feb 7, 2022 | The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (avail... |
| CVE-2021-25108 | HIGH | 7.1 | 0.4% | Feb 7, 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_block... |
| CVE-2021-25106 | MEDIUM | 5.4 | 0.6% | Feb 7, 2022 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1... |
| CVE-2021-25105 | MEDIUM | 4.8 | 0.6% | Feb 7, 2022 | The Ivory Search WordPress plugin before 5.4.1 does not escape some of the Form settings, which could allow high privile... |
| CVE-2021-25103 | MEDIUM | 4.7 | 0.7% | Feb 7, 2022 | The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in... |
| CVE-2021-25096 | MEDIUM | 6.5 | 1.0% | Feb 7, 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the... |
| CVE-2021-25095 | HIGH | 7.1 | 0.5% | Feb 7, 2022 | The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc... |
| CVE-2021-25084 | MEDIUM | 4.3 | 0.6% | Feb 7, 2022 | The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do n... |
| CVE-2021-25077 | MEDIUM | 6.1 | 0.9% | Feb 7, 2022 | The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before ou... |
| CVE-2021-25029 | MEDIUM | 4.8 | 0.6% | Feb 7, 2022 | The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which co... |
| CVE-2021-25004 | MEDIUM | 4.9 | 1.1% | Feb 7, 2022 | The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u... |
| CVE-2021-24993 | MEDIUM | 6.5 | 0.5% | Feb 7, 2022 | The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act... |
| CVE-2021-24947 | MEDIUM | 6.5 | 3.0% | Feb 7, 2022 | The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_r... |
| CVE-2021-24928 | MEDIUM | 6.5 | 0.9% | Feb 7, 2022 | The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_or... |
| CVE-2021-24880 | MEDIUM | 5.4 | 0.6% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which c... |
| CVE-2021-24879 | HIGH | 8.8 | 0.6% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any san... |
| CVE-2021-24878 | MEDIUM | 6.1 | 1.2% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back i... |
| CVE-2021-24843 | MEDIUM | 6.5 | 0.5% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could all... |
| CVE-2021-24839 | HIGH | 7.5 | 1.2% | Feb 7, 2022 | The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti... |
| CVE-2021-46389 | HIGH | 7.5 | 1.2% | Feb 7, 2022 | IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by ... |
| CVE-2021-46359 | HIGH | 7.5 | 1.2% | Feb 7, 2022 | FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successf... |
| CVE-2021-43929 | MEDIUM | 5.4 | 0.6% | Feb 7, 2022 | Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in work... |
| CVE-2021-43928 | HIGH | 8.8 | 1.9% | Feb 7, 2022 | Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending... |
| CVE-2021-43927 | CRITICAL | 9.8 | 0.9% | Feb 7, 2022 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Security Managemen... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now