2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39995MEDIUM6.5Some Huawei products use the OpenHpi software for hardware management. A function that parses data returned by OpenHpi c...
CVE-2021-43693CRITICAL9.8vesta 0.9.8-24 is affected by a file inclusion vulnerability in file web/add/user/index.php.
CVE-2021-43692MEDIUM6.1youtube-php-mirroring (last update Jun 9, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in file ytprox...
CVE-2021-43695MEDIUM6.1issabelPBX version 2.11 is affected by a Cross Site Scripting (XSS) vulnerability. In file page.backup_restore.php, the ...
CVE-2021-43697MEDIUM6.1Workerman-ThinkPHP-Redis (last update Mar 16, 2018) is affected by a Cross Site Scripting (XSS) vulnerability. In file C...
CVE-2021-43696MEDIUM6.1twmap v2.91_v4.33 is affected by a Cross Site Scripting (XSS) vulnerability. In file list.php, the exit function will te...
CVE-2021-43698MEDIUM6.1phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the e...
CVE-2021-24927MEDIUM5.4The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup...
CVE-2021-24918MEDIUM5.4The Smash Balloon Social Post Feed WordPress plugin before 4.0.1 did not have any privilege or nonce validation before s...
CVE-2021-24915CRITICAL9.8The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the...
CVE-2021-24908MEDIUM6.1The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attr...
CVE-2021-24899MEDIUM4.8The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could all...
CVE-2021-24889HIGH7.2The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which coul...
CVE-2021-24883MEDIUM5.4The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which co...
CVE-2021-24876MEDIUM6.1The Registrations for the Events Calendar WordPress plugin before 2.7.5 does not escape the v parameter before outputtin...
CVE-2021-24860HIGH7.2The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before u...
CVE-2021-24842MEDIUM5.4The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contrib...
CVE-2021-24822MEDIUM5.4The Stylish Cost Calculator WordPress plugin before 7.0.4 does not have any authorisation and CSRF checks on some of its...
CVE-2021-24811MEDIUM4.8The Shop Page WP WordPress plugin before 1.2.8 does not sanitise and escape some of the Product fields, allowing high pr...
CVE-2021-24768MEDIUM4.8The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, a...
CVE-2021-24755HIGH8.8The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL stateme...
CVE-2021-24751MEDIUM5.4The GenerateBlocks WordPress plugin before 1.4.0 does not validate the generateblocks/container block's tagName attribut...
CVE-2021-24749MEDIUM4.3The URL Shortify WordPress plugin before 1.5.1 does not have CSRF check in place when bulk-deleting links or groups, whi...
CVE-2021-24748HIGH8.8The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET pa...
CVE-2021-24745MEDIUM5.4The About Author Box WordPress plugin before 1.0.2 does not sanitise and escape the Social Profiles field values before ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now