2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24333 | MEDIUM | 6.5 | 0.8% | Jun 1, 2021 | The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its se... |
| CVE-2021-24331 | MEDIUM | 4.8 | 0.7% | Jun 1, 2021 | The Smooth Scroll Page Up/Down Buttons WordPress plugin before 1.4 did not properly sanitise and validate its settings, ... |
| CVE-2021-24330 | MEDIUM | 4.8 | 0.7% | Jun 1, 2021 | The Funnel Builder by CartFlows – Create High Converting Sales Funnels For WordPress plugin before 1.6.13 did not saniti... |
| CVE-2021-24329 | MEDIUM | 5.4 | 3.3% | Jun 1, 2021 | The WP Super Cache WordPress plugin before 1.7.3 did not properly sanitise its wp_cache_location parameter in its settin... |
| CVE-2021-24328 | MEDIUM | 6.2 | 0.6% | Jun 1, 2021 | The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any... |
| CVE-2021-24322 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output ... |
| CVE-2021-24321 | CRITICAL | 9.8 | 66.6% | Jun 1, 2021 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not sanitise the bt_bb_listing_field_price_range_to, bt... |
| CVE-2021-24320 | MEDIUM | 6.1 | 10.8% | Jun 1, 2021 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise and escape its listing_list_view,... |
| CVE-2021-24319 | MEDIUM | 5.4 | 1.7% | Jun 1, 2021 | The Bello - Directory & Listing WordPress theme before 1.6.0 did not properly sanitise its post_excerpt parameter before... |
| CVE-2021-24318 | MEDIUM | 6.5 | 1.0% | Jun 1, 2021 | The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user maki... |
| CVE-2021-24317 | MEDIUM | 6.1 | 0.9% | Jun 1, 2021 | The Listeo WordPress theme before 1.6.11 did not properly sanitise some parameters in its Search, Booking Confirmation a... |
| CVE-2021-24316 | MEDIUM | 6.1 | 6.4% | Jun 1, 2021 | The search feature of the Mediumish WordPress theme through 1.0.47 does not properly sanitise it's 's' GET parameter bef... |
| CVE-2021-24313 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them ... |
| CVE-2021-24312 | HIGH | 7.2 | 1.7% | Jun 1, 2021 | The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p... |
| CVE-2021-24311 | HIGH | 8.8 | 1.8% | Jun 1, 2021 | The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr... |
| CVE-2021-24310 | MEDIUM | 4.8 | 1.1% | Jun 1, 2021 | The Photo Gallery by 10Web - Mobile-Friendly Image Gallery WordPress plugin before 1.5.67 did not properly sanitise the ... |
| CVE-2021-24309 | MEDIUM | 5.4 | 0.7% | Jun 1, 2021 | The "Schedule Name" input in the Weekly Schedule WordPress plugin before 3.4.3 general options did not properly sanitize... |
| CVE-2021-23388 | MEDIUM | 5.3 | 1.7% | Jun 1, 2021 | The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDo... |
| CVE-2021-20585 | MEDIUM | 5.3 | 1.0% | Jun 1, 2021 | IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in furth... |
| CVE-2021-20576 | HIGH | 7.5 | 2.5% | Jun 1, 2021 | IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could c... |
| CVE-2021-20575 | LOW | 3.3 | 0.3% | Jun 1, 2021 | IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. ... |
| CVE-2021-20306 | MEDIUM | 4.3 | 0.7% | Jun 1, 2021 | A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the na... |
| CVE-2021-23021 | MEDIUM | 5.5 | 0.2% | Jun 1, 2021 | The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with c... |
| CVE-2021-23020 | MEDIUM | 5.5 | 0.3% | Jun 1, 2021 | The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which co... |
| CVE-2021-23019 | HIGH | 7.8 | 0.2% | Jun 1, 2021 | The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt fil... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now