2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24230HIGH8.1The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0...
CVE-2021-24229CRITICAL9.6The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX act...
CVE-2021-24228CRITICAL9.6The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin befo...
CVE-2021-24227HIGH7.5The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that...
CVE-2021-24226HIGH7.5In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible ...
CVE-2021-24225MEDIUM5.4The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & C...
CVE-2021-24224HIGH8.8The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticate...
CVE-2021-24223CRITICAL9.8The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from th...
CVE-2021-24222CRITICAL9.8The WP-Curriculo Vitae Free WordPress plugin through 6.3 suffers from an arbitrary file upload issue in page where the [...
CVE-2021-24221HIGH8.8The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the r...
CVE-2021-24220CRITICAL9.1Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, ...
CVE-2021-24219MEDIUM5.3The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline ...
CVE-2021-24218HIGH8.8The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3...
CVE-2021-24217HIGH8.1The run_action function of the Facebook for WordPress plugin before 3.0.0 deserializes user supplied data making it poss...
CVE-2021-24215CRITICAL9.8An Improper Access Control vulnerability was discovered in the Controlled Admin Access WordPress plugin before 1.5.2. Un...
CVE-2021-24213MEDIUM6.1The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-S...
CVE-2021-24200MEDIUM6.5The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user...
CVE-2021-24199MEDIUM6.5The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user...
CVE-2021-24198HIGH8.1The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privil...
CVE-2021-24197HIGH8.1The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privil...
CVE-2021-23370CRITICAL9.8This affects the package swiper before 6.5.1.
CVE-2021-23369CRITICAL9.8The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling optio...
CVE-2021-23368MEDIUM5.3The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during s...
CVE-2021-23371HIGH7.5This affects the package chrono-node before 2.2.4. It hangs on a date-like string with lots of embedded spaces.
CVE-2021-29379HIGH8.8An issue was discovered on D-Link DIR-802 A1 devices through 1.00b05. Universal Plug and Play (UPnP) is enabled by defau...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now