2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4422MEDIUM4.3The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2021-4421MEDIUM4.3The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2021-4420MEDIUM4.3The Sell Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5....
CVE-2021-4419MEDIUM4.3The WP-Backgrounds Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin...
CVE-2021-4417MEDIUM4.3The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Reque...
CVE-2021-4416MEDIUM4.3The wp-mpdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1. Th...
CVE-2021-4415MEDIUM4.3The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin...
CVE-2021-4414MEDIUM4.3The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up ...
CVE-2021-4413MEDIUM4.3The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, ...
CVE-2021-4412MEDIUM4.3The WP Prayer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5. ...
CVE-2021-4411MEDIUM4.3The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to...
CVE-2021-4410MEDIUM4.3The Qtranslate Slug plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2021-4409MEDIUM4.3The WooCommerce Etsy Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and...
CVE-2021-4408MEDIUM4.3The DW Question & Answer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2021-4407MEDIUM4.3The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3....
CVE-2021-4406HIGH7.2An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager...
CVE-2021-42083MEDIUM5.4An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager...
CVE-2021-42082HIGH7.8Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl ...
CVE-2021-42081HIGH7.2An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDR...
CVE-2021-42080HIGH7.4An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDR...
CVE-2021-42079MEDIUM4.9An authenticated administrator is able to prepare an alert that is able to execute an SSRF attack. This is exclusively w...
CVE-2021-39014MEDIUM5.4IBM Cloud Object System 3.15.8.97 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed...
CVE-2021-32495CRITICAL9.1Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afte...
CVE-2021-32494HIGH7.5Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create m...
CVE-2021-33798MEDIUM6.5A null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now