2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25874HIGH7.5AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter...
CVE-2021-27644HIGH8.8In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Onl...
CVE-2021-41973MEDIUM6.5In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. T...
CVE-2021-24813MEDIUM4.8The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi...
CVE-2021-24809HIGH8.8The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_bett...
CVE-2021-24808MEDIUM6.1The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'sub...
CVE-2021-24799MEDIUM4.3The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could ...
CVE-2021-24794MEDIUM4.8The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an ...
CVE-2021-24793MEDIUM4.8The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before ou...
CVE-2021-24789MEDIUM4.8The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute ...
CVE-2021-24781MEDIUM4.3The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrar...
CVE-2021-24773MEDIUM4.8The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputt...
CVE-2021-24770MEDIUM6.5The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX a...
CVE-2021-24757MEDIUM5.3The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a...
CVE-2021-24742MEDIUM6.5The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the ...
CVE-2021-24723MEDIUM5.4The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing us...
CVE-2021-24722MEDIUM4.8The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating...
CVE-2021-24717HIGH8.8The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber role...
CVE-2021-24716MEDIUM5.4The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users ...
CVE-2021-24715MEDIUM4.8The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which coul...
CVE-2021-24685MEDIUM5.4The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does...
CVE-2021-24682MEDIUM5.4The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, whi...
CVE-2021-24624MEDIUM4.8The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or es...
CVE-2021-24572MEDIUM4.3The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are ...
CVE-2021-24570MEDIUM4.3The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which inter...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now