2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24623MEDIUM4.8The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape ...
CVE-2021-24621MEDIUM4.8The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be ...
CVE-2021-24620HIGH8.8The WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin through 2.2.5 does not check fo...
CVE-2021-24619MEDIUM4.8The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing maliciou...
CVE-2021-24614MEDIUM4.8The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it...
CVE-2021-24605MEDIUM5.4The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenti...
CVE-2021-24586MEDIUM4.3The Per page add to head WordPress plugin before 1.4.4 is lacking any CSRF check when saving its settings, which could a...
CVE-2021-24560MEDIUM6.1The Software License Manager WordPress plugin before 4.4.8 does not sanitise or escape the edit_record parameter before ...
CVE-2021-24523MEDIUM5.4The Daily Prayer Time WordPress plugin before 2021.08.10 does not sanitise or escape some of its settings before outputt...
CVE-2021-24510MEDIUM6.1The MF Gig Calendar WordPress plugin before 1.2 does not sanitise and escape the id GET parameter before outputting back...
CVE-2021-24508MEDIUM6.1The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter ...
CVE-2021-24493CRITICAL9.8The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authe...
CVE-2021-24491HIGH8.8The Fileviewer WordPress plugin through 2.2 does not have CSRF checks in place when performing actions such as upload an...
CVE-2021-24490MEDIUM6.8The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import...
CVE-2021-24431MEDIUM4.3The Language Bar Flags WordPress plugin through 1.0.8 does not have any CSRF in place when saving its settings and did n...
CVE-2021-32135MEDIUM5.5The trak_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ...
CVE-2021-32132MEDIUM5.5The abst_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a ...
CVE-2021-29643MEDIUM5.4PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a co...
CVE-2021-32137MEDIUM5.5Heap buffer overflow in the URL_GetProtocolType function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of s...
CVE-2021-32134MEDIUM5.5The gf_odf_desc_copy function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via...
CVE-2021-32136HIGH7.8Heap buffer overflow in the print_udta function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or...
CVE-2021-40214MEDIUM5.4Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.
CVE-2021-22528MEDIUM5.4Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-22527HIGH7.5Information leakage vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-22526MEDIUM6.1Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now