2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4387HIGH8.8The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.1...
CVE-2021-4386MEDIUM4.3The WP Security Question plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi...
CVE-2021-4385MEDIUM4.3The WP Private Content Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl...
CVE-2021-4384MEDIUM4.3The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions...
CVE-2021-42307MEDIUM4.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2021-34506MEDIUM6.1Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2021-34475MEDIUM5.4Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-31982HIGH8.8Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2021-25828MEDIUM6.1Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /...
CVE-2021-25827CRITICAL9.8Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-addres...
CVE-2021-31937HIGH8.2Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-30205MEDIUM5.3Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenti...
CVE-2021-30203MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers ...
CVE-2021-31635CRITICAL9.8Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary cod...
CVE-2021-0945CRITICAL9.8In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via Phy...
CVE-2021-0701CRITICAL9.8In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer ove...
CVE-2021-31280MEDIUM6.1An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter.
CVE-2021-46889MEDIUM6.1The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other p...
CVE-2021-4380CRITICAL9.8The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on t...
CVE-2021-4379MEDIUM6.5The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch...
CVE-2021-4337HIGH8.8Sixteen XforWooCommerce Add-On Plugins for WordPress are vulnerable to authorization bypass due to a missing capability ...
CVE-2021-4383MEDIUM4.3The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to page content injection in versions up to, and includi...
CVE-2021-4382HIGH8.8The Recently plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the fet...
CVE-2021-4381CRITICAL9.8The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, a...
CVE-2021-4378MEDIUM5.4The WP Quick FrontEnd Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now