2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22552MEDIUM5.5An untrusted memory read vulnerability in Asylo versions up to 0.6.1 allows an untrusted attacker to pass a syscall numb...
CVE-2021-20332MEDIUM4.4Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in...
CVE-2021-37216MEDIUM6.1QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript w...
CVE-2021-34574MEDIUM4.3In MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 a...
CVE-2021-24504MEDIUM6.1The WP LMS – Best WordPress LMS Plugin WordPress plugin through 1.1.2 does not properly sanitise or validate its User Fi...
CVE-2021-24503MEDIUM5.4The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode...
CVE-2021-24498MEDIUM6.1The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET param...
CVE-2021-24496MEDIUM6.1The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and success...
CVE-2021-24488MEDIUM6.1The slider import search feature and tab parameter of the Post Grid WordPress plugin before 2.1.8 settings are not prope...
CVE-2021-24481MEDIUM4.8The Any Hostname WordPress plugin through 1.0.6 does not sanitise or escape its "Allowed hosts" setting, leading to an a...
CVE-2021-24480MEDIUM4.8The Event Geek WordPress plugin through 2.5.2 does not sanitise or escape its "Use your own " setting before outputting ...
CVE-2021-24479MEDIUM4.8The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them bac...
CVE-2021-24478MEDIUM5.4The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outpu...
CVE-2021-24477MEDIUM6.1The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a...
CVE-2021-24476MEDIUM5.4The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings befor...
CVE-2021-24474MEDIUM6.1The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refr...
CVE-2021-24473MEDIUM5.4The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_ima...
CVE-2021-24470MEDIUM5.4The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, ...
CVE-2021-24468MEDIUM5.4The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScri...
CVE-2021-24464MEDIUM5.4The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise som...
CVE-2021-24455MEDIUM5.4The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of A...
CVE-2021-24450MEDIUM4.8The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin befor...
CVE-2021-24448MEDIUM4.8The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Mo...
CVE-2021-24444MEDIUM4.8The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Tax...
CVE-2021-24443MEDIUM5.4The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin be...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now