2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24383MEDIUM5.4The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the M...
CVE-2021-24379MEDIUM5.3The Comments Like Dislike WordPress plugin before 1.1.4 allows users to like/dislike posted comments, however does not p...
CVE-2021-24378MEDIUM4.8The Autoptimize WordPress plugin before 2.7.8 does not check for malicious files such as .html in the archive uploaded v...
CVE-2021-24377HIGH8.1The Autoptimize WordPress plugin before 2.7.8 attempts to remove potential malicious files from the extracted archive up...
CVE-2021-24376CRITICAL9.8The Autoptimize WordPress plugin before 2.7.8 attempts to delete malicious files (such as .php) form the uploaded archiv...
CVE-2021-24374MEDIUM5.3The Jetpack Carousel module of the JetPack WordPress plugin before 9.8 allows users to create a "carousel" type image ga...
CVE-2021-24373MEDIUM6.1The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyvalue...
CVE-2021-24372MEDIUM6.1The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the $_SERVER['RE...
CVE-2021-24370CRITICAL9.8The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, res...
CVE-2021-24369MEDIUM5.4In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, h...
CVE-2021-24367MEDIUM5.4The WP Config File Editor WordPress plugin through 1.7.1 was affected by an Authenticated Stored Cross-Site Scripting (X...
CVE-2021-24366MEDIUM5.4The Admin Columns WordPress plugin before 4.3 and Admin Columns Pro WordPress plugin before 5.5.1 do not sanitise and es...
CVE-2021-24364MEDIUM6.1The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather...
CVE-2021-24361CRITICAL9.8In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sani...
CVE-2021-24339MEDIUM5.4The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cros...
CVE-2021-24338MEDIUM5.4The Pods – Custom Content Types and Fields WordPress plugin before 2.7.27 was vulnerable to an Authenticated Stored Cros...
CVE-2021-32697MEDIUM5.3neos/forms is an open source framework to build web forms. By crafting a special `GET` request containing a valid form s...
CVE-2021-21422MEDIUM6.1mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: h...
CVE-2021-26461CRITICAL9.8Apache Nuttx Versions prior to 10.1.0 are vulnerable to integer wrap-around in functions malloc, realloc and memalign. T...
CVE-2021-0533HIGH7In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local esc...
CVE-2021-0532HIGH7In memory management driver, there is a possible memory corruption due to a race condition. This could lead to local esc...
CVE-2021-0531HIGH7.8In memory management driver, there is a possible memory corruption due to a use after free. This could lead to local esc...
CVE-2021-0530HIGH7.8In memory management driver, there is a possible out of bounds write due to uninitialized data. This could lead to local...
CVE-2021-0529HIGH7.8In memory management driver, there is a possible memory corruption due to improper locking. This could lead to local esc...
CVE-2021-0528HIGH7.8In memory management driver, there is a possible memory corruption due to a double free. This could lead to local escala...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now