2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25017 | MEDIUM | 6.1 | 1.0% | Jan 24, 2022 | The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attrib... |
| CVE-2021-25015 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the hi... |
| CVE-2021-25013 | MEDIUM | 6.5 | 0.4% | Jan 24, 2022 | The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA... |
| CVE-2021-25008 | MEDIUM | 6.1 | 2.3% | Jan 24, 2022 | The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it b... |
| CVE-2021-24989 | MEDIUM | 6.5 | 0.5% | Jan 24, 2022 | The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure tha... |
| CVE-2021-24985 | MEDIUM | 6.1 | 1.1% | Jan 24, 2022 | The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type pa... |
| CVE-2021-24976 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it ... |
| CVE-2021-24974 | MEDIUM | 5.4 | 0.6% | Jan 24, 2022 | The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some o... |
| CVE-2021-24968 | MEDIUM | 5.7 | 0.4% | Jan 24, 2022 | The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq ... |
| CVE-2021-24965 | MEDIUM | 5.4 | 0.6% | Jan 24, 2022 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_... |
| CVE-2021-24936 | HIGH | 8 | 0.5% | Jan 24, 2022 | The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise an... |
| CVE-2021-24923 | MEDIUM | 6.1 | 0.8% | Jan 24, 2022 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape t... |
| CVE-2021-24906 | HIGH | 7.5 | 1.5% | Jan 24, 2022 | The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, ... |
| CVE-2021-24865 | HIGH | 7.2 | 1.5% | Jan 24, 2022 | The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters ... |
| CVE-2021-24858 | HIGH | 7.2 | 1.3% | Jan 24, 2022 | The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before... |
| CVE-2021-24733 | MEDIUM | 4.3 | 0.8% | Jan 24, 2022 | The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view othe... |
| CVE-2021-24696 | HIGH | 8.8 | 0.6% | Jan 24, 2022 | The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to ... |
| CVE-2021-24694 | MEDIUM | 5.4 | 0.6% | Jan 24, 2022 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perfor... |
| CVE-2021-24423 | MEDIUM | 4.8 | 0.6% | Jan 24, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a... |
| CVE-2021-39293 | HIGH | 7.5 | 6.9% | Jan 24, 2022 | In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many fil... |
| CVE-2021-30636 | CRITICAL | 9.8 | 1.5% | Jan 24, 2022 | In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled ... |
| CVE-2021-26706 | CRITICAL | 9.8 | 1.9% | Jan 24, 2022 | An issue was discovered in lib_mem.c in Micrium uC/OS uC/LIB 1.38.x and 1.39.00. The following memory allocation functio... |
| CVE-2021-46024 | CRITICAL | 9.8 | 1.0% | Jan 23, 2022 | Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in c... |
| CVE-2021-45380 | MEDIUM | 6.1 | 2.5% | Jan 23, 2022 | AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php |
| CVE-2021-4103 | MEDIUM | 5.4 | 0.7% | Jan 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now