2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41111 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to versions 3.4.... |
| CVE-2021-4222 | MEDIUM | 4.8 | 0.8% | Feb 28, 2022 | The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege ... |
| CVE-2021-25118 | MEDIUM | 5.3 | 5.8% | Feb 28, 2022 | The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in po... |
| CVE-2021-25112 | MEDIUM | 6.1 | 2.2% | Feb 28, 2022 | The WHMCS Bridge WordPress plugin before 6.4b does not sanitise and escape the error parameter before outputting it back... |
| CVE-2021-25081 | MEDIUM | 6.5 | 0.6% | Feb 28, 2022 | The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX action... |
| CVE-2021-25042 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in... |
| CVE-2021-25034 | MEDIUM | 6.1 | 0.8% | Feb 28, 2022 | The WP User WordPress plugin before 7.0 does not sanitise and escape some parameters in pages where the [wp_user] shortc... |
| CVE-2021-25011 | MEDIUM | 5.7 | 0.4% | Feb 28, 2022 | The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most ... |
| CVE-2021-24994 | MEDIUM | 6.1 | 1.2% | Feb 28, 2022 | The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, a... |
| CVE-2021-24977 | MEDIUM | 6.1 | 1.5% | Feb 28, 2022 | The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assign... |
| CVE-2021-24971 | MEDIUM | 5.4 | 0.6% | Feb 28, 2022 | The WP Responsive Menu WordPress plugin before 3.1.7.1 does not have capability and CSRF checks in the wpr_live_update A... |
| CVE-2021-24933 | MEDIUM | 5.4 | 0.6% | Feb 28, 2022 | The Dynamic Widgets WordPress plugin through 1.5.16 does not escape the prefix parameter before outputting it back in an... |
| CVE-2021-24920 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, whic... |
| CVE-2021-24913 | MEDIUM | 4.3 | 0.5% | Feb 28, 2022 | The Logo Showcase with Slick Slider WordPress plugin before 2.0.1 does not have CSRF check in the lswss_save_attachment_... |
| CVE-2021-24903 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which cou... |
| CVE-2021-24901 | MEDIUM | 4.8 | 5.1% | Feb 28, 2022 | The Security Audit WordPress plugin through 1.0.0 does not sanitise and escape the Data Id setting, which could allow hi... |
| CVE-2021-24898 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The EditableTable WordPress plugin through 0.1.4 does not sanitise and escape any of the Table and Column fields, which ... |
| CVE-2021-24820 | MEDIUM | 6.5 | 2.9% | Feb 28, 2022 | The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ ... |
| CVE-2021-24730 | MEDIUM | 4.3 | 0.3% | Feb 28, 2022 | The Logo Showcase with Slick Slider WordPress plugin before 1.2.5 does not have CSRF and authorisation checks in the lsw... |
| CVE-2021-24689 | MEDIUM | 4.9 | 1.3% | Feb 28, 2022 | The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to downl... |
| CVE-2021-24688 | MEDIUM | 4.3 | 0.4% | Feb 28, 2022 | The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls,... |
| CVE-2021-43945 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permission... |
| CVE-2021-46702 | MEDIUM | 5.5 | 0.4% | Feb 26, 2022 | Tor Browser 9.0.7 on Windows 10 build 10586 is vulnerable to information disclosure. This could allow local attackers to... |
| CVE-2021-23495 | MEDIUM | 6.1 | 0.9% | Feb 25, 2022 | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parame... |
| CVE-2021-42244 | MEDIUM | 6.1 | 0.6% | Feb 25, 2022 | A cross-site scripting (XSS) vulnerability in PaquitoSoftware Notimoo v1.2 allows attackers to execute arbitrary web scr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now