2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24479 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them bac... |
| CVE-2021-24478 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Bookshelf WordPress plugin through 2.0.4 does not sanitise or escape its "Paypal email address" setting before outpu... |
| CVE-2021-24477 | MEDIUM | 6.1 | 0.4% | Aug 2, 2021 | The Migrate Users WordPress plugin through 1.0.1 does not sanitise or escape its Delimiter option before outputting in a... |
| CVE-2021-24476 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Steam Group Viewer WordPress plugin through 2.1 does not sanitise or escape its "Steam Group Address" settings befor... |
| CVE-2021-24474 | MEDIUM | 6.1 | 0.7% | Aug 2, 2021 | The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refr... |
| CVE-2021-24473 | MEDIUM | 5.4 | 0.8% | Aug 2, 2021 | The User Profile Picture WordPress plugin before 2.6.0 was affected by an IDOR issue, allowing users with the upload_ima... |
| CVE-2021-24472 | CRITICAL | 9.8 | 56.6% | Aug 2, 2021 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional... |
| CVE-2021-24470 | MEDIUM | 5.4 | 0.5% | Aug 2, 2021 | The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, ... |
| CVE-2021-24468 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The Leaflet Map WordPress plugin before 3.0.0 does not escape some shortcode attributes before they are used in JavaScri... |
| CVE-2021-24464 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise som... |
| CVE-2021-24463 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did ... |
| CVE-2021-24462 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPr... |
| CVE-2021-24461 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_faqs() function in the FAQ Builder AYS WordPress plugin before 1.3.6 did not use whitelist or validate the order... |
| CVE-2021-24460 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist ... |
| CVE-2021-24459 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or v... |
| CVE-2021-24458 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use... |
| CVE-2021-24457 | HIGH | 8.8 | 1.4% | Aug 2, 2021 | The get_portfolios() and get_portfolio_attributes() functions in the class-portfolio-responsive-gallery-list-table.php a... |
| CVE-2021-24456 | HIGH | 7.2 | 1.3% | Aug 2, 2021 | The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters bef... |
| CVE-2021-24455 | MEDIUM | 5.4 | 0.7% | Aug 2, 2021 | The Tutor LMS – eLearning and online course solution WordPress plugin before 1.9.2 did not escape the Summary field of A... |
| CVE-2021-24450 | MEDIUM | 4.8 | 0.7% | Aug 2, 2021 | The User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin befor... |
| CVE-2021-24448 | MEDIUM | 4.8 | 0.6% | Aug 2, 2021 | The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.8 does not sanitise or escape its 'Mo... |
| CVE-2021-24444 | MEDIUM | 4.8 | 2.3% | Aug 2, 2021 | The TaxoPress – Create and Manage Taxonomies, Tags, Categories WordPress plugin before 3.0.7.2 does not sanitise its Tax... |
| CVE-2021-24443 | MEDIUM | 5.4 | 0.6% | Aug 2, 2021 | The About Me widget of the Youzify – BuddyPress Community, User Profile, Social Network & Membership WordPress plugin be... |
| CVE-2021-24430 | HIGH | 7.2 | 1.7% | Aug 2, 2021 | The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude... |
| CVE-2021-24428 | MEDIUM | 4.8 | 0.5% | Aug 2, 2021 | The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving an... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now