2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24711HIGH8.8The del_reistered_domains AJAX action of the Software License Manager WordPress plugin before 4.5.1 does not have any CS...
CVE-2021-24709MEDIUM4.8The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size...
CVE-2021-24691MEDIUM4.8The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it ...
CVE-2021-24690MEDIUM5.4The Chained Quiz WordPress plugin before 1.2.7.2 does not properly sanitize or escape inputs in the plugin's settings.
CVE-2021-24683MEDIUM5.4The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do...
CVE-2021-24681MEDIUM4.8The Duplicate Page WordPress plugin through 4.4.2 does not sanitise or escape the Duplicate Post Suffix settings before ...
CVE-2021-24656MEDIUM4.8The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outp...
CVE-2021-24651HIGH7.5The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_po...
CVE-2021-24577MEDIUM5.4The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not properly sanitize inputs submitted by authen...
CVE-2021-24576MEDIUM5.4The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordio...
CVE-2021-24563MEDIUM6.1The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allow...
CVE-2021-24546HIGH8.8The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Condit...
CVE-2021-24545MEDIUM5.4The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing t...
CVE-2021-40889CRITICAL9.8CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php fi...
CVE-2021-35060MEDIUM5.3/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response difference...
CVE-2021-35059MEDIUM6.1OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.
CVE-2021-41832HIGH7.5It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apach...
CVE-2021-41831MEDIUM5.3It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to ...
CVE-2021-41830HIGH7.5It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All ve...
CVE-2021-41801HIGH8.8The ReplaceText extension through 1.41 for MediaWiki has Incorrect Access Control. When a user is blocked after submitti...
CVE-2021-41800MEDIUM5.3MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visi...
CVE-2021-41799HIGH7.5MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQ...
CVE-2021-41798MEDIUM6.1MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Se...
CVE-2021-42139CRITICAL9.8Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.
CVE-2021-42137MEDIUM5.3An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requiremen...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now