2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24355MEDIUM4.3In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, the lack of capability checks and insufficient...
CVE-2021-24354HIGH8.8A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks W...
CVE-2021-24353HIGH8.8The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or n...
CVE-2021-24352HIGH8.8The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or n...
CVE-2021-24351MEDIUM6.1The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not p...
CVE-2021-24350MEDIUM6.1The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabil...
CVE-2021-24349MEDIUM6.1This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But fi...
CVE-2021-24348HIGH7.2The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Admi...
CVE-2021-24347HIGH8.8The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempt...
CVE-2021-24346MEDIUM5.4The Stock in & out WordPress plugin through 1.0.4 has a search functionality, the lowest accessible level to it being co...
CVE-2021-24345MEDIUM6.6The page lists-management feature of the Sendit WP Newsletter WordPress plugin through 2.5.1, available to Administrator...
CVE-2021-24341HIGH8.8When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_...
CVE-2021-21439MEDIUM6.5DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage...
CVE-2021-23394CRITICAL9.8The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in ...
CVE-2021-34682LOW3.7Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-31812MEDIUM5.5In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects A...
CVE-2021-31811MEDIUM5.5In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue a...
CVE-2021-32557HIGH7.1It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symli...
CVE-2021-32556LOW3.3It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modifie...
CVE-2021-32555MEDIUM5.5It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function ...
CVE-2021-32554MEDIUM5.5It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function ...
CVE-2021-32553MEDIUM5.5It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function ...
CVE-2021-32552MEDIUM5.5It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function ...
CVE-2021-32551MEDIUM5.5It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function ...
CVE-2021-32550MEDIUM5.5It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now