2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25017MEDIUM6.1The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attrib...
CVE-2021-25015MEDIUM6.1The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the hi...
CVE-2021-25013MEDIUM6.5The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA...
CVE-2021-25008MEDIUM6.1The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it b...
CVE-2021-24989MEDIUM6.5The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure tha...
CVE-2021-24985MEDIUM6.1The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type pa...
CVE-2021-24976MEDIUM6.1The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it ...
CVE-2021-24974MEDIUM5.4The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some o...
CVE-2021-24968MEDIUM5.7The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq ...
CVE-2021-24965MEDIUM5.4The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_...
CVE-2021-24936HIGH8The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise an...
CVE-2021-24923MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape t...
CVE-2021-24906HIGH7.5The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, ...
CVE-2021-24865HIGH7.2The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters ...
CVE-2021-24858HIGH7.2The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before...
CVE-2021-24733MEDIUM4.3The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view othe...
CVE-2021-24696HIGH8.8The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to ...
CVE-2021-24694MEDIUM5.4The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perfor...
CVE-2021-24423MEDIUM4.8The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a...
CVE-2021-39293HIGH7.5In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many fil...
CVE-2021-30636CRITICAL9.8In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled ...
CVE-2021-26706CRITICAL9.8An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functio...
CVE-2021-46024CRITICAL9.8Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in c...
CVE-2021-45380MEDIUM6.1AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
CVE-2021-4103MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now