2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31852MEDIUM6.1A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated a...
CVE-2021-31851MEDIUM6.1A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated a...
CVE-2021-25986MEDIUM5.4In Django-wiki, versions 0.0.20 to 0.7.8 are vulnerable to Stored Cross-Site Scripting (XSS) in Notifications Section. A...
CVE-2021-24894MEDIUM6.5The Reviews Plus WordPress plugin before 1.2.14 does not validate the submitted rating, allowing submission of long inte...
CVE-2021-24892HIGH8.8Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remot...
CVE-2021-24891MEDIUM6.1The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM v...
CVE-2021-24888MEDIUM4.8The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high...
CVE-2021-24882MEDIUM4.8The Slideshow Gallery WordPress plugin before 1.7.4 does not sanitise and escape the Slide "Title", "Description", and G...
CVE-2021-24877HIGH7.2The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a ...
CVE-2021-24875MEDIUM6.1The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter...
CVE-2021-24873MEDIUM6.1The Tutor LMS WordPress plugin before 1.9.11 does not sanitise and escape user input before outputting back in attribute...
CVE-2021-24830MEDIUM4.8The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, all...
CVE-2021-24812MEDIUM5.4The BetterLinks WordPress plugin before 1.2.6 does not sanitise and escape some of imported link fields, which could lea...
CVE-2021-24729MEDIUM5.4The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow...
CVE-2021-24713MEDIUM4.8The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do n...
CVE-2021-24703MEDIUM5.7The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate ...
CVE-2021-24700MEDIUM4.8The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high...
CVE-2021-24668MEDIUM4.3The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrator...
CVE-2021-24644HIGH7.5The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the ...
CVE-2021-24641HIGH8.1The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative ac...
CVE-2021-21561MEDIUM5.5Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a maliciou...
CVE-2021-43019HIGH7.8Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources lev...
CVE-2021-3672MEDIUM5.6A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Se...
CVE-2021-37102HIGH8.8There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default ce...
CVE-2021-37035HIGH7.5There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the ap...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now