2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24925 | MEDIUM | 6.1 | 0.8% | Dec 13, 2021 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider par... |
| CVE-2021-24922 | CRITICAL | 9 | 0.5% | Dec 13, 2021 | The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as w... |
| CVE-2021-24896 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Caldera Forms WordPress plugin before 1.9.5 does not sanitise and escape the Form Name before outputting it in attri... |
| CVE-2021-24872 | MEDIUM | 6.5 | 1.0% | Dec 13, 2021 | The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other p... |
| CVE-2021-24871 | MEDIUM | 5.4 | 0.7% | Dec 13, 2021 | The Get Custom Field Values WordPress plugin before 4.0.1 does not escape custom fields before outputting them in the pa... |
| CVE-2021-24863 | CRITICAL | 9.8 | 1.6% | Dec 13, 2021 | The WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots WordPress plugin before ... |
| CVE-2021-24861 | HIGH | 7.2 | 1.3% | Dec 13, 2021 | The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using i... |
| CVE-2021-24859 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | The User Meta Shortcodes WordPress plugin through 0.5 registers a shortcode that allows any user with a role as low as c... |
| CVE-2021-24857 | CRITICAL | 9.8 | 1.8% | Dec 13, 2021 | The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which ... |
| CVE-2021-24855 | MEDIUM | 5.4 | 0.6% | Dec 13, 2021 | The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their conte... |
| CVE-2021-24848 | HIGH | 8.8 | 1.3% | Dec 13, 2021 | The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authentic... |
| CVE-2021-24845 | MEDIUM | 6.5 | 1.0% | Dec 13, 2021 | The Improved Include Page WordPress plugin through 1.2 allows passing shortcode attributes with post_type & post_status ... |
| CVE-2021-24836 | MEDIUM | 4.3 | 0.3% | Dec 13, 2021 | The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when upda... |
| CVE-2021-24819 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users... |
| CVE-2021-24818 | MEDIUM | 4.3 | 0.4% | Dec 13, 2021 | The WP Limits WordPress plugin through 1.0 does not have CSRF check when saving its settings, allowing attacker to make ... |
| CVE-2021-24817 | MEDIUM | 5.4 | 0.6% | Dec 13, 2021 | The Ultimate NoFollow WordPress plugin through 1.4.8 does not sanitise and escape the href attribute of its shortcodes, ... |
| CVE-2021-24795 | MEDIUM | 6.5 | 0.5% | Dec 13, 2021 | The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleti... |
| CVE-2021-24792 | MEDIUM | 6.1 | 1.2% | Dec 13, 2021 | The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a templat... |
| CVE-2021-24790 | MEDIUM | 4.3 | 0.4% | Dec 13, 2021 | The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks... |
| CVE-2021-24784 | MEDIUM | 6.5 | 0.5% | Dec 13, 2021 | The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could al... |
| CVE-2021-24782 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could... |
| CVE-2021-24780 | MEDIUM | 4.3 | 0.4% | Dec 13, 2021 | The Single Post Exporter WordPress plugin through 1.1.1 does not have CSRF checks when saving its settings, which could ... |
| CVE-2021-24771 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Inspirational Quote Rotator WordPress plugin through 1.0.0 does not sanitize and escape some of its quote fields whe... |
| CVE-2021-24756 | MEDIUM | 6.1 | 1.3% | Dec 13, 2021 | The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from lo... |
| CVE-2021-24747 | HIGH | 7.2 | 1.5% | Dec 13, 2021 | The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now