2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24230 | HIGH | 8.1 | 0.6% | Apr 12, 2021 | The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0... |
| CVE-2021-24229 | CRITICAL | 9.6 | 1.8% | Apr 12, 2021 | The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX act... |
| CVE-2021-24228 | CRITICAL | 9.6 | 1.9% | Apr 12, 2021 | The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin befo... |
| CVE-2021-24227 | HIGH | 7.5 | 5.9% | Apr 12, 2021 | The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that... |
| CVE-2021-24226 | HIGH | 7.5 | 5.4% | Apr 12, 2021 | In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible ... |
| CVE-2021-24225 | MEDIUM | 5.4 | 0.7% | Apr 12, 2021 | The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & C... |
| CVE-2021-24224 | HIGH | 8.8 | 1.9% | Apr 12, 2021 | The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticate... |
| CVE-2021-24223 | CRITICAL | 9.8 | 2.2% | Apr 12, 2021 | The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from th... |
| CVE-2021-24222 | CRITICAL | 9.8 | 2.4% | Apr 12, 2021 | The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [... |
| CVE-2021-24221 | HIGH | 8.8 | 1.9% | Apr 12, 2021 | The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the r... |
| CVE-2021-24220 | CRITICAL | 9.1 | 3.9% | Apr 12, 2021 | Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, ... |
| CVE-2021-24219 | MEDIUM | 5.3 | 2.1% | Apr 12, 2021 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline ... |
| CVE-2021-24218 | HIGH | 8.8 | 0.7% | Apr 12, 2021 | The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3... |
| CVE-2021-24217 | HIGH | 8.1 | 3.5% | Apr 12, 2021 | The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it poss... |
| CVE-2021-24215 | CRITICAL | 9.8 | 9.7% | Apr 12, 2021 | An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Un... |
| CVE-2021-24213 | MEDIUM | 6.1 | 1.4% | Apr 12, 2021 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-S... |
| CVE-2021-24200 | MEDIUM | 6.5 | 1.3% | Apr 12, 2021 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user... |
| CVE-2021-24199 | MEDIUM | 6.5 | 1.3% | Apr 12, 2021 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user... |
| CVE-2021-24198 | HIGH | 8.1 | 1.5% | Apr 12, 2021 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privil... |
| CVE-2021-24197 | HIGH | 8.1 | 1.2% | Apr 12, 2021 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privil... |
| CVE-2021-23370 | CRITICAL | 9.8 | 2.2% | Apr 12, 2021 | This affects the package swiper before 6.5.1. |
| CVE-2021-23369 | CRITICAL | 9.8 | 7.0% | Apr 12, 2021 | The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling optio... |
| CVE-2021-23368 | MEDIUM | 5.3 | 3.5% | Apr 12, 2021 | The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during s... |
| CVE-2021-23371 | HIGH | 7.5 | 2.0% | Apr 12, 2021 | This affects the package chrono-node before 2.2.4. It hangs on a date-like string with lots of embedded spaces. |
| CVE-2021-29379 | HIGH | 8.8 | 3.5% | Apr 12, 2021 | An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by defau... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now