2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24210MEDIUM6.1There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request t...
CVE-2021-24208MEDIUM5.4The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML,...
CVE-2021-24207MEDIUM4.3By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to ...
CVE-2021-24206MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) ac...
CVE-2021-24205MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) acce...
CVE-2021-24204MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) ac...
CVE-2021-24203MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accept...
CVE-2021-24202MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accept...
CVE-2021-24201MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accept...
CVE-2021-24196MEDIUM5.4The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page a...
CVE-2021-24187MEDIUM5.4The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to refle...
CVE-2021-24186MEDIUM6.5The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course soluti...
CVE-2021-24185MEDIUM6.5The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7...
CVE-2021-24183MEDIUM6.5The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress...
CVE-2021-24182MEDIUM6.5The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution Wor...
CVE-2021-24181MEDIUM6.5The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin ...
CVE-2021-24180MEDIUM5.4Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Refle...
CVE-2021-24177MEDIUM5.4In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint ...
CVE-2021-24176MEDIUM5.4The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output ...
CVE-2021-24173MEDIUM6.1The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan...
CVE-2021-24172MEDIUM4.3The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan...
CVE-2021-24169MEDIUM6.1This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order da...
CVE-2021-24168MEDIUM5.4The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subje...
CVE-2021-24166MEDIUM5.4The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPre...
CVE-2021-24165MEDIUM6.1In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now