2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24535MEDIUM6.1The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising...
CVE-2021-24534MEDIUM5.4The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before out...
CVE-2021-24526MEDIUM5.4The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not esca...
CVE-2021-24519MEDIUM4.8The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' fie...
CVE-2021-24518MEDIUM4.8The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, all...
CVE-2021-24512MEDIUM5.4The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) ...
CVE-2021-24471MEDIUM5.4The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, ...
CVE-2021-24466MEDIUM6.1The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logg...
CVE-2021-24445MEDIUM5.5The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit...
CVE-2021-24411MEDIUM6.1The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not san...
CVE-2021-24410MEDIUM6.1The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, an...
CVE-2021-24380MEDIUM4.3The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing ...
CVE-2021-24363MEDIUM4.9The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded f...
CVE-2021-24362MEDIUM6.1The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded S...
CVE-2021-35936MEDIUM5.3If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor...
CVE-2021-3707MEDIUM5.5D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification...
CVE-2021-38713MEDIUM5.4imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.
CVE-2021-38709MEDIUM6.1In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for...
CVE-2021-38708MEDIUM5.4In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.
CVE-2021-26086MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr...
CVE-2021-38699MEDIUM5.4TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
CVE-2021-37326MEDIUM5.3NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
CVE-2021-36791MEDIUM5.3The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registrat...
CVE-2021-36790MEDIUM6.1The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
CVE-2021-36788MEDIUM5.4The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now