2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41111MEDIUM5.4Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4....
CVE-2021-4222MEDIUM4.8The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege ...
CVE-2021-25118MEDIUM5.3The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in po...
CVE-2021-25112MEDIUM6.1The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back...
CVE-2021-25081MEDIUM6.5The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX action...
CVE-2021-25042MEDIUM5.4The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in...
CVE-2021-25034MEDIUM6.1The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortc...
CVE-2021-25011MEDIUM5.7The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most ...
CVE-2021-24994MEDIUM6.1The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, a...
CVE-2021-24977MEDIUM6.1The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assign...
CVE-2021-24971MEDIUM5.4The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update A...
CVE-2021-24933MEDIUM5.4The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an...
CVE-2021-24920MEDIUM4.8The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, whic...
CVE-2021-24913MEDIUM4.3The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_...
CVE-2021-24903MEDIUM4.8The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which cou...
CVE-2021-24901MEDIUM4.8The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow hi...
CVE-2021-24898MEDIUM4.8The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which ...
CVE-2021-24820MEDIUM6.5The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ ...
CVE-2021-24730MEDIUM4.3The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lsw...
CVE-2021-24689MEDIUM4.9The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to downl...
CVE-2021-24688MEDIUM4.3The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls,...
CVE-2021-43945MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permission...
CVE-2021-46702MEDIUM5.5Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to...
CVE-2021-23495MEDIUM6.1The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parame...
CVE-2021-42244MEDIUM6.1A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now