2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3729MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3728MEDIUM6.5firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3694CRITICAL9.6LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an...
CVE-2021-3693CRITICAL9.6LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL ...
CVE-2021-35465LOW3.4Certain Arm products before 2021-08-23 do not properly consider the effect of exceptions on a VLLDM instruction. A Non-s...
CVE-2021-33598MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in all versions of F-Secure Atlant whereby the SAVAPI component u...
CVE-2021-24658MEDIUM4.8The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing hi...
CVE-2021-24602HIGH8.8The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set...
CVE-2021-24574MEDIUM4.8The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privile...
CVE-2021-24571MEDIUM5.4The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when g...
CVE-2021-24565HIGH8.8The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings,...
CVE-2021-24564MEDIUM5.4The WPFront Scroll Top WordPress plugin before 2.0.6.07225 does not sanitise or escape its Image ALT setting before outp...
CVE-2021-24562HIGH7.5The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 ...
CVE-2021-24561MEDIUM5.4The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in t...
CVE-2021-24558MEDIUM5.4The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise,...
CVE-2021-24557HIGH7.2The update functionality in the rslider_page uses an rs_id POST parameter which is not validated, sanitised or escaped b...
CVE-2021-24556MEDIUM6.1The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sani...
CVE-2021-24555HIGH8.8The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter wh...
CVE-2021-24554HIGH7.2The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter be...
CVE-2021-24553HIGH7.2The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before u...
CVE-2021-24552HIGH7.2The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parame...
CVE-2021-24551CRITICAL9.8The Edit Comments WordPress plugin through 0.3 does not sanitise, validate or escape the jal_edit_comments GET parameter...
CVE-2021-24550HIGH7.2The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter befor...
CVE-2021-24549MEDIUM4.9The AceIDE WordPress plugin through 2.6.2 does not sanitise or validate the user input which is appended to system paths...
CVE-2021-24547MEDIUM5.4The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now