2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40261MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via th...
CVE-2021-40260MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parame...
CVE-2021-41170CRITICAL9.8neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures d...
CVE-2021-39420MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exist in VFront 0.99.5 via the (1) s parameter in search_all.php and...
CVE-2021-40577MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an...
CVE-2021-24844HIGH7.2The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL s...
CVE-2021-24840MEDIUM5.3The Squaretype WordPress theme before 3.0.4 allows unauthenticated users to manipulate the query_vars used to retrieve t...
CVE-2021-24835HIGH8.8The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before...
CVE-2021-24832MEDIUM4.3The WP SEO Redirect 301 WordPress plugin before 2.3.2 does not have CSRF in place when deleting redirects, which could a...
CVE-2021-24829HIGH8.8The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to t...
CVE-2021-24827CRITICAL9.8The Asgaros Forum WordPress plugin before 1.15.13 does not validate and escape user input when subscribing to a topic be...
CVE-2021-24816MEDIUM4.3The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX ...
CVE-2021-24807MEDIUM5.4The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting atta...
CVE-2021-24806MEDIUM4.3The wpDiscuz WordPress plugin before 7.3.4 does check for CSRF when adding, editing and deleting comments, which could a...
CVE-2021-24801MEDIUM4.3The WP Survey Plus WordPress plugin through 1.0 does not have any authorisation and CSRF checks in place in its AJAX act...
CVE-2021-24798MEDIUM6.1The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it bac...
CVE-2021-24791HIGH7.2The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" req...
CVE-2021-24788MEDIUM6.5The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are avai...
CVE-2021-24783MEDIUM6.5The Post Expirator WordPress plugin before 2.6.0 does not have proper capability checks in place, which could allow user...
CVE-2021-24767MEDIUM6.5The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF w...
CVE-2021-24766MEDIUM6.5The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place whe...
CVE-2021-24731CRITICAL9.8The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres...
CVE-2021-24721MEDIUM6.5The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed ...
CVE-2021-24710MEDIUM4.8The Print-O-Matic WordPress plugin before 2.0.3 does not escape some of its settings before outputting them in attribute...
CVE-2021-24708MEDIUM4.8The Export any WordPress data to XML/CSV WordPress plugin before 1.3.1 does not escape its Export's Name before outputti...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now