2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24604 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The Availability Calendar WordPress plugin before 1.2.2 does not sanitise or escape its Category Names before outputting... |
| CVE-2021-24600 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The WP Dialog WordPress plugin through 1.2.5.5 does not sanitise and escape some of its settings before outputting them ... |
| CVE-2021-24597 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The You Shang WordPress plugin through 1.0.1 does not escape its qrcode links settings, which result into Stored Cross-S... |
| CVE-2021-24596 | MEDIUM | 4.8 | 2.7% | Sep 20, 2021 | The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowin... |
| CVE-2021-24587 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them ... |
| CVE-2021-24585 | MEDIUM | 6.5 | 1.1% | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (... |
| CVE-2021-24584 | MEDIUM | 5.4 | 0.5% | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when updating a times... |
| CVE-2021-24583 | MEDIUM | 4.3 | 1.6% | Sep 20, 2021 | The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a times... |
| CVE-2021-24582 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it i... |
| CVE-2021-24530 | MEDIUM | 4.8 | 0.6% | Sep 20, 2021 | The Alojapro Widget WordPress plugin through 1.1.15 doesn't properly sanitise its Custom CSS settings, allowing high pri... |
| CVE-2021-24525 | MEDIUM | 5.4 | 0.6% | Sep 20, 2021 | The Shortcodes Ultimate WordPress plugin before 5.10.2 allows users with Contributor roles to perform stored XSS via sho... |
| CVE-2021-24511 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_... |
| CVE-2021-24404 | HIGH | 8.8 | 4.7% | Sep 20, 2021 | The options.php file of the WP-Board WordPress plugin through 1.1 beta accepts a postid parameter which is not sanitised... |
| CVE-2021-24403 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitis... |
| CVE-2021-24402 | HIGH | 7.2 | 4.6% | Sep 20, 2021 | The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not san... |
| CVE-2021-24401 | HIGH | 7.2 | 4.6% | Sep 20, 2021 | The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is ... |
| CVE-2021-24400 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanit... |
| CVE-2021-24399 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, ... |
| CVE-2021-24398 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is n... |
| CVE-2021-24397 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | The edit functionality in the MicroCopy WordPress plugin through 1.1.0 makes a get request to fetch the related option. ... |
| CVE-2021-24396 | HIGH | 7.2 | 1.5% | Sep 20, 2021 | A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or val... |
| CVE-2021-38300 | HIGH | 7.8 | 0.6% | Sep 20, 2021 | arch/mips/net/bpf_jit.c in the Linux kernel before 5.4.10 can generate undesirable machine code when transforming unpriv... |
| CVE-2021-40690 | HIGH | 7.5 | 7.4% | Sep 19, 2021 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "... |
| CVE-2021-41073 | HIGH | 7.8 | 1.7% | Sep 19, 2021 | loop_rw_iter in fs/io_uring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IOR... |
| CVE-2021-23441 | — | — | — | Sep 19, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now