2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3755 | — | — | — | Oct 18, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-24760 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow u... |
| CVE-2021-24754 | HIGH | 7.2 | 1.3% | Oct 18, 2021 | The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it... |
| CVE-2021-24752 | MEDIUM | 5.7 | 0.4% | Oct 18, 2021 | Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, wh... |
| CVE-2021-24743 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding post... |
| CVE-2021-24740 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, w... |
| CVE-2021-24736 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Word... |
| CVE-2021-24735 | MEDIUM | 6.5 | 0.6% | Oct 18, 2021 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers t... |
| CVE-2021-24734 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could... |
| CVE-2021-24732 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The PDF Flipbook, 3D Flipbook WordPress – DearFlip WordPress plugin before 1.7.10 does not escape the class attribute of... |
| CVE-2021-24702 | MEDIUM | 4.8 | 0.7% | Oct 18, 2021 | The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course setting... |
| CVE-2021-24684 | HIGH | 8.8 | 4.3% | Oct 18, 2021 | The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary... |
| CVE-2021-24677 | MEDIUM | 5.3 | 1.2% | Oct 18, 2021 | The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow u... |
| CVE-2021-24675 | MEDIUM | 6.5 | 0.6% | Oct 18, 2021 | The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [av... |
| CVE-2021-24672 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allow... |
| CVE-2021-24642 | MEDIUM | 6.5 | 0.6% | Oct 18, 2021 | The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform an... |
| CVE-2021-24622 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fi... |
| CVE-2021-24617 | MEDIUM | 6.1 | 0.7% | Oct 18, 2021 | The GamePress WordPress plugin through 1.1.0 does not escape the op_edit POST parameter before outputting it back in mul... |
| CVE-2021-24615 | MEDIUM | 5.4 | 0.4% | Oct 18, 2021 | The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in pl... |
| CVE-2021-24612 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The Sociable WordPress plugin through 4.3.4.1 does not sanitise or escape some of its settings before outputting them in... |
| CVE-2021-24595 | MEDIUM | 6.5 | 0.5% | Oct 18, 2021 | The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape... |
| CVE-2021-24516 | MEDIUM | 4.8 | 0.6% | Oct 18, 2021 | The PlanSo Forms WordPress plugin through 2.6.3 does not escape the title of its Form before outputting it in attributes... |
| CVE-2021-24416 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its sh... |
| CVE-2021-24415 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Polo Video Gallery – Best wordpress video gallery plugin WordPress plugin through 1.2 does not sanitise or validate ... |
| CVE-2021-24413 | MEDIUM | 5.4 | 0.6% | Oct 18, 2021 | The Easy Twitter Feed WordPress plugin before 1.2 does not sanitise or validate the parameters from its shortcode, allow... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now