2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40261 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via th... |
| CVE-2021-40260 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parame... |
| CVE-2021-41170 | CRITICAL | 9.8 | 1.5% | Nov 8, 2021 | neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d... |
| CVE-2021-39420 | MEDIUM | 6.1 | 0.6% | Nov 8, 2021 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and... |
| CVE-2021-40577 | MEDIUM | 5.4 | 1.6% | Nov 8, 2021 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an... |
| CVE-2021-24844 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL s... |
| CVE-2021-24840 | MEDIUM | 5.3 | 1.1% | Nov 8, 2021 | The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t... |
| CVE-2021-24835 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before... |
| CVE-2021-24832 | MEDIUM | 4.3 | 0.4% | Nov 8, 2021 | The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could a... |
| CVE-2021-24829 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to t... |
| CVE-2021-24827 | CRITICAL | 9.8 | 12.9% | Nov 8, 2021 | The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic be... |
| CVE-2021-24816 | MEDIUM | 4.3 | 0.7% | Nov 8, 2021 | The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX ... |
| CVE-2021-24807 | MEDIUM | 5.4 | 1.4% | Nov 8, 2021 | The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting atta... |
| CVE-2021-24806 | MEDIUM | 4.3 | 0.5% | Nov 8, 2021 | The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could a... |
| CVE-2021-24801 | MEDIUM | 4.3 | 0.4% | Nov 8, 2021 | The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX act... |
| CVE-2021-24798 | MEDIUM | 6.1 | 0.8% | Nov 8, 2021 | The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it bac... |
| CVE-2021-24791 | HIGH | 7.2 | 5.0% | Nov 8, 2021 | The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" req... |
| CVE-2021-24788 | MEDIUM | 6.5 | 0.9% | Nov 8, 2021 | The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are avai... |
| CVE-2021-24783 | MEDIUM | 6.5 | 0.8% | Nov 8, 2021 | The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow user... |
| CVE-2021-24767 | MEDIUM | 6.5 | 0.5% | Nov 8, 2021 | The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF w... |
| CVE-2021-24766 | MEDIUM | 6.5 | 0.5% | Nov 8, 2021 | The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place whe... |
| CVE-2021-24731 | CRITICAL | 9.8 | 7.5% | Nov 8, 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres... |
| CVE-2021-24721 | MEDIUM | 6.5 | 0.9% | Nov 8, 2021 | The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed ... |
| CVE-2021-24710 | MEDIUM | 4.8 | 0.7% | Nov 8, 2021 | The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute... |
| CVE-2021-24708 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now