2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41660CRITICAL9.8SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to ...
CVE-2021-41659CRITICAL9.8SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL ...
CVE-2021-35005LOW3.3This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An ...
CVE-2021-41658MEDIUM5.4Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute ...
CVE-2021-4088HIGH7.2SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.1...
CVE-2021-41472CRITICAL9.8SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbi...
CVE-2021-41471CRITICAL9.8SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers...
CVE-2021-40909CRITICAL9.6Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tut...
CVE-2021-40908CRITICAL9.8SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows atta...
CVE-2021-40907CRITICAL9.8SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to...
CVE-2021-40596CRITICAL9.8SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to e...
CVE-2021-44981HIGH8.8In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it int...
CVE-2021-25083MEDIUM6.1The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outp...
CVE-2021-25080MEDIUM6.1The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved v...
CVE-2021-25079MEDIUM6.1The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id,...
CVE-2021-25078MEDIUM6.1The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests l...
CVE-2021-25076HIGH8.8The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in...
CVE-2021-25074MEDIUM6.1The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr...
CVE-2021-25073HIGH8.8The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, al...
CVE-2021-25062MEDIUM6.1The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outp...
CVE-2021-25049MEDIUM4.8The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing h...
CVE-2021-25045HIGH7.2The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in ...
CVE-2021-25035MEDIUM6.1The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error paramete...
CVE-2021-25031MEDIUM6.1The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7...
CVE-2021-25028MEDIUM6.1The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirec...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now