2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24604MEDIUM4.8The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting...
CVE-2021-24600MEDIUM4.8The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them ...
CVE-2021-24597MEDIUM5.4The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-S...
CVE-2021-24596MEDIUM4.8The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin...
CVE-2021-24587MEDIUM5.4The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them ...
CVE-2021-24585MEDIUM6.5The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (...
CVE-2021-24584MEDIUM5.4The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a times...
CVE-2021-24583MEDIUM4.3The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a times...
CVE-2021-24582MEDIUM5.4The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it i...
CVE-2021-24530MEDIUM4.8The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri...
CVE-2021-24525MEDIUM5.4The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via sho...
CVE-2021-24511HIGH7.2The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_...
CVE-2021-24404HIGH8.8The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised...
CVE-2021-24403HIGH7.2The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitis...
CVE-2021-24402HIGH7.2The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not san...
CVE-2021-24401HIGH7.2The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is ...
CVE-2021-24400HIGH7.2The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanit...
CVE-2021-24399HIGH7.2The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, ...
CVE-2021-24398HIGH7.2The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is n...
CVE-2021-24397HIGH7.2The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. ...
CVE-2021-24396HIGH7.2A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or val...
CVE-2021-38300HIGH7.8arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unpriv...
CVE-2021-40690HIGH7.5All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "...
CVE-2021-41073HIGH7.8loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IOR...
CVE-2021-23441Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now