2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24333MEDIUM6.5The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its se...
CVE-2021-24331MEDIUM4.8The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, ...
CVE-2021-24330MEDIUM4.8The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not saniti...
CVE-2021-24329MEDIUM5.4The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settin...
CVE-2021-24328MEDIUM6.2The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any...
CVE-2021-24322MEDIUM5.4The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output ...
CVE-2021-24321CRITICAL9.8The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt...
CVE-2021-24320MEDIUM6.1The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view,...
CVE-2021-24319MEDIUM5.4The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before...
CVE-2021-24318MEDIUM6.5The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki...
CVE-2021-24317MEDIUM6.1The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation a...
CVE-2021-24316MEDIUM6.1The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter bef...
CVE-2021-24313MEDIUM5.4The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them ...
CVE-2021-24312HIGH7.2The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p...
CVE-2021-24311HIGH8.8The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr...
CVE-2021-24310MEDIUM4.8The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the ...
CVE-2021-24309MEDIUM5.4The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize...
CVE-2021-23388MEDIUM5.3The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDo...
CVE-2021-20585MEDIUM5.3IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in furth...
CVE-2021-20576HIGH7.5IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could c...
CVE-2021-20575LOW3.3IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. ...
CVE-2021-20306MEDIUM4.3A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the na...
CVE-2021-23021MEDIUM5.5The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with c...
CVE-2021-23020MEDIUM5.5The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which co...
CVE-2021-23019HIGH7.8The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now