2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-30205MEDIUM5.3Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenti...
CVE-2021-30203MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers ...
CVE-2021-31280MEDIUM6.1An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter.
CVE-2021-46889MEDIUM6.1The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other p...
CVE-2021-4379MEDIUM6.5The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch...
CVE-2021-4383MEDIUM4.3The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and includi...
CVE-2021-4378MEDIUM5.4The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in...
CVE-2021-4377MEDIUM6.5The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2...
CVE-2021-4376MEDIUM4.3The WooCommerce Multi Currency plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu...
CVE-2021-4375MEDIUM4.3The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t...
CVE-2021-4373MEDIUM4.3The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5...
CVE-2021-4372MEDIUM6.1The WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi...
CVE-2021-4371MEDIUM4.3The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Setting Changs in versions up to, and including, 5.5....
CVE-2021-4369MEDIUM5.3The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and...
CVE-2021-4367MEDIUM5.4The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Opti...
CVE-2021-4366MEDIUM4.3The PWA for WP & AMP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the...
CVE-2021-4365MEDIUM6.1The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions ...
CVE-2021-4364MEDIUM4.3The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check ...
CVE-2021-4363MEDIUM6.1The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and...
CVE-2021-4359MEDIUM5.3The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up t...
CVE-2021-4358MEDIUM6.1The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in ...
CVE-2021-4357MEDIUM5.3The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing ...
CVE-2021-4355MEDIUM5.3The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on th...
CVE-2021-4352MEDIUM5.3The JobSearch WP Job Board plugin for WordPress is vulnerable to authorization bypass due to a missing capability check ...
CVE-2021-4351MEDIUM5.3The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now