2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3755Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-24760MEDIUM5.4The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow u...
CVE-2021-24754HIGH7.2The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it...
CVE-2021-24752MEDIUM5.7Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, wh...
CVE-2021-24743MEDIUM5.4The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding post...
CVE-2021-24740MEDIUM4.8The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, w...
CVE-2021-24736MEDIUM4.8The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Word...
CVE-2021-24735MEDIUM6.5The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers t...
CVE-2021-24734MEDIUM5.4The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could...
CVE-2021-24732MEDIUM5.4The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of...
CVE-2021-24702MEDIUM4.8The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting...
CVE-2021-24684HIGH8.8The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary...
CVE-2021-24677MEDIUM5.3The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow u...
CVE-2021-24675MEDIUM6.5The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [av...
CVE-2021-24672MEDIUM5.4The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allow...
CVE-2021-24642MEDIUM6.5The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform an...
CVE-2021-24622MEDIUM4.8The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fi...
CVE-2021-24617MEDIUM6.1The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in mul...
CVE-2021-24615MEDIUM5.4The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in pl...
CVE-2021-24612MEDIUM4.8The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in...
CVE-2021-24595MEDIUM6.5The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape...
CVE-2021-24516MEDIUM4.8The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes...
CVE-2021-24416MEDIUM5.4The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its sh...
CVE-2021-24415MEDIUM5.4The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate ...
CVE-2021-24413MEDIUM5.4The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allow...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now