2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32613MEDIUM5.5In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
CVE-2021-24291MEDIUM6.1The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cr...
CVE-2021-24287MEDIUM6.1The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before ...
CVE-2021-24286MEDIUM6.1The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab paramete...
CVE-2021-24285CRITICAL9.8The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available...
CVE-2021-24284CRITICAL9.8The Kaswara Modern VC Addons WordPress plugin through 3.0.1 allows unauthenticated arbitrary file upload via the 'upload...
CVE-2021-24283MEDIUM5.4The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, lead...
CVE-2021-24282MEDIUM6.3In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could...
CVE-2021-24281MEDIUM4.3In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could...
CVE-2021-24280HIGH8.8In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could...
CVE-2021-24279MEDIUM6.5In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the...
CVE-2021-24278HIGH7.5In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce ...
CVE-2021-24277MEDIUM5.4The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settin...
CVE-2021-24195HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer ...
CVE-2021-24194HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit F...
CVE-2021-24193HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time ...
CVE-2021-24192HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plu...
CVE-2021-24191HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site...
CVE-2021-24190HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Ma...
CVE-2021-24189HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptc...
CVE-2021-24188HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection...
CVE-2021-30183HIGH7.5Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when runni...
CVE-2021-32051HIGH7.5Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id par...
CVE-2021-31922HIGH7.5An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to s...
CVE-2021-33026CRITICAL9.8The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code e...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now