2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25874 | HIGH | 7.5 | 1.9% | Nov 1, 2021 | AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter... |
| CVE-2021-27644 | HIGH | 8.8 | 1.9% | Nov 1, 2021 | In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Onl... |
| CVE-2021-41973 | MEDIUM | 6.5 | 4.3% | Nov 1, 2021 | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. T... |
| CVE-2021-24813 | MEDIUM | 4.8 | 0.7% | Nov 1, 2021 | The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi... |
| CVE-2021-24809 | HIGH | 8.8 | 0.7% | Nov 1, 2021 | The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_bett... |
| CVE-2021-24808 | MEDIUM | 6.1 | 0.9% | Nov 1, 2021 | The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'sub... |
| CVE-2021-24799 | MEDIUM | 4.3 | 0.5% | Nov 1, 2021 | The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could ... |
| CVE-2021-24794 | MEDIUM | 4.8 | 0.7% | Nov 1, 2021 | The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an ... |
| CVE-2021-24793 | MEDIUM | 4.8 | 0.6% | Nov 1, 2021 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.6.12 does not escape the Feed URL added to a campaign before ou... |
| CVE-2021-24789 | MEDIUM | 4.8 | 0.6% | Nov 1, 2021 | The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute ... |
| CVE-2021-24781 | MEDIUM | 4.3 | 0.8% | Nov 1, 2021 | The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrar... |
| CVE-2021-24773 | MEDIUM | 4.8 | 2.8% | Nov 1, 2021 | The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputt... |
| CVE-2021-24770 | MEDIUM | 6.5 | 0.8% | Nov 1, 2021 | The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX a... |
| CVE-2021-24757 | MEDIUM | 5.3 | 1.0% | Nov 1, 2021 | The Stylish Price List WordPress plugin before 6.9.0 does not perform capability checks in its spl_upload_ser_img AJAX a... |
| CVE-2021-24742 | MEDIUM | 6.5 | 0.8% | Nov 1, 2021 | The Logo Slider and Showcase WordPress plugin before 1.3.37 allows Editor users to update the plugin's settings via the ... |
| CVE-2021-24723 | MEDIUM | 5.4 | 0.6% | Nov 1, 2021 | The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing us... |
| CVE-2021-24722 | MEDIUM | 4.8 | 0.6% | Nov 1, 2021 | The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating... |
| CVE-2021-24717 | HIGH | 8.8 | 1.3% | Nov 1, 2021 | The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber role... |
| CVE-2021-24716 | MEDIUM | 5.4 | 0.6% | Nov 1, 2021 | The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users ... |
| CVE-2021-24715 | MEDIUM | 4.8 | 0.6% | Nov 1, 2021 | The WP Sitemap Page WordPress plugin before 1.7.0 does not properly sanitise and escape some of its settings, which coul... |
| CVE-2021-24685 | MEDIUM | 5.4 | 0.5% | Nov 1, 2021 | The Flat Preloader WordPress plugin before 1.5.4 does not enforce nonce checks when saving its settings, as well as does... |
| CVE-2021-24682 | MEDIUM | 5.4 | 0.6% | Nov 1, 2021 | The Cool Tag Cloud WordPress plugin before 2.26 does not escape the style attribute of the cool_tag_cloud shortcode, whi... |
| CVE-2021-24624 | MEDIUM | 4.8 | 0.6% | Nov 1, 2021 | The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or es... |
| CVE-2021-24572 | MEDIUM | 4.3 | 0.5% | Nov 1, 2021 | The Accept Donations with PayPal WordPress plugin before 1.3.1 provides a function to create donation buttons which are ... |
| CVE-2021-24570 | MEDIUM | 4.3 | 0.5% | Nov 1, 2021 | The Accept Donations with PayPal WordPress plugin before 1.3.1 offers a function to create donation buttons, which inter... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now