2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24527CRITICAL9.8The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to rese...
CVE-2021-24526MEDIUM5.4The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder WordPress plugin before 1.13.60 does not esca...
CVE-2021-24519MEDIUM4.8The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' fie...
CVE-2021-24518MEDIUM4.8The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, all...
CVE-2021-24512MEDIUM5.4The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) ...
CVE-2021-24471MEDIUM5.4The YouTube Embed WordPress plugin before 5.2.2 does not validate, escape or sanitise some of its shortcode attributes, ...
CVE-2021-24466MEDIUM6.1The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logg...
CVE-2021-24445MEDIUM5.5The My Site Audit WordPress plugin through 1.2.4 does not sanitise or escape the Audit Name field when creating an audit...
CVE-2021-24411MEDIUM6.1The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not san...
CVE-2021-24410MEDIUM6.1The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, an...
CVE-2021-24380MEDIUM4.3The Shantz WordPress QOTD WordPress plugin through 1.2.2 is lacking any CSRF check when updating its settings, allowing ...
CVE-2021-24363MEDIUM4.9The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded f...
CVE-2021-24362MEDIUM6.1The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded S...
CVE-2021-35936MEDIUM5.3If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor...
CVE-2021-33193HIGH7.5A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request spl...
CVE-2021-23423HIGH7.5This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include...
CVE-2021-23422HIGH7.8This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Comma...
CVE-2021-3708HIGH7.8D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticate...
CVE-2021-3707MEDIUM5.5D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification...
CVE-2021-38713MEDIUM5.4imgURL 2.31 allows XSS via an X-Forwarded-For HTTP header.
CVE-2021-38712HIGH7.5OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to bl...
CVE-2021-38711HIGH7.5In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
CVE-2021-38709MEDIUM6.1In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via the staff_messaging messaging system for...
CVE-2021-38708MEDIUM5.4In ocProducts Composr CMS before 10.0.38, an attacker can inject JavaScript via Comcode for XSS.
CVE-2021-26086MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now