2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24706MEDIUM4.8The Qwizcards – online quizzes and flashcards WordPress plugin before 3.62 does not properly sanitize and escape some of...
CVE-2021-24701MEDIUM4.8The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managin...
CVE-2021-24698MEDIUM4.3The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumb...
CVE-2021-24697MEDIUM6.1The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm...
CVE-2021-24695HIGH7.5The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any au...
CVE-2021-24693CRITICAL9The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputti...
CVE-2021-24674MEDIUM6.5The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could a...
CVE-2021-24669HIGH8.8The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter...
CVE-2021-24664MEDIUM4.8The School Management System – WPSchoolPress WordPress plugin before 2.1.17 sanitise some fields using sanitize_text_fie...
CVE-2021-24647HIGH8.1The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPres...
CVE-2021-24646MEDIUM4.8The Booking.com Banner Creator WordPress plugin before 1.4.3 does not properly sanitize inputs when creating banners, wh...
CVE-2021-24645MEDIUM4.8The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Pro...
CVE-2021-24631HIGH8.8The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in...
CVE-2021-24630HIGH8.8The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQ...
CVE-2021-24629HIGH7.2The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before usi...
CVE-2021-24628HIGH7.2The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL ...
CVE-2021-24627HIGH7.2The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in...
CVE-2021-24626HIGH8.8The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allow...
CVE-2021-24625HIGH7.2The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from...
CVE-2021-24616MEDIUM4.8The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead...
CVE-2021-24607MEDIUM4.8The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to...
CVE-2021-24594MEDIUM4.8The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of...
CVE-2021-24575HIGH8.8The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared s...
CVE-2021-24537HIGH7.2The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened...
CVE-2021-29843MEDIUM6.5IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing mes...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now