2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24706 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of... |
| CVE-2021-24701 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin... |
| CVE-2021-24698 | MEDIUM | 4.3 | 0.7% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb... |
| CVE-2021-24697 | MEDIUM | 6.1 | 0.8% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm... |
| CVE-2021-24695 | HIGH | 7.5 | 1.6% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any au... |
| CVE-2021-24693 | CRITICAL | 9 | 1.2% | Nov 8, 2021 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputti... |
| CVE-2021-24674 | MEDIUM | 6.5 | 0.5% | Nov 8, 2021 | The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could a... |
| CVE-2021-24669 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter... |
| CVE-2021-24664 | MEDIUM | 4.8 | 2.4% | Nov 8, 2021 | The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_fie... |
| CVE-2021-24647 | HIGH | 8.1 | 8.4% | Nov 8, 2021 | The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres... |
| CVE-2021-24646 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh... |
| CVE-2021-24645 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro... |
| CVE-2021-24631 | HIGH | 8.8 | 1.5% | Nov 8, 2021 | The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in... |
| CVE-2021-24630 | HIGH | 8.8 | 1.5% | Nov 8, 2021 | The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQ... |
| CVE-2021-24629 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before usi... |
| CVE-2021-24628 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL ... |
| CVE-2021-24627 | HIGH | 7.2 | 6.6% | Nov 8, 2021 | The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in... |
| CVE-2021-24626 | HIGH | 8.8 | 0.7% | Nov 8, 2021 | The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allow... |
| CVE-2021-24625 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from... |
| CVE-2021-24616 | MEDIUM | 4.8 | 0.7% | Nov 8, 2021 | The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead... |
| CVE-2021-24607 | MEDIUM | 4.8 | 0.6% | Nov 8, 2021 | The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to... |
| CVE-2021-24594 | MEDIUM | 4.8 | 0.7% | Nov 8, 2021 | The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of... |
| CVE-2021-24575 | HIGH | 8.8 | 1.3% | Nov 8, 2021 | The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared s... |
| CVE-2021-24537 | HIGH | 7.2 | 1.5% | Nov 8, 2021 | The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened... |
| CVE-2021-29843 | MEDIUM | 6.5 | 0.9% | Nov 8, 2021 | IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing mes... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now