2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24207 | MEDIUM | 4.3 | 0.7% | Apr 5, 2021 | By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to ... |
| CVE-2021-24206 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) ac... |
| CVE-2021-24205 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) acce... |
| CVE-2021-24204 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) ac... |
| CVE-2021-24203 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accept... |
| CVE-2021-24202 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accept... |
| CVE-2021-24201 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accept... |
| CVE-2021-24196 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page a... |
| CVE-2021-24187 | MEDIUM | 5.4 | 0.6% | Apr 5, 2021 | The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to refle... |
| CVE-2021-24186 | MEDIUM | 6.5 | 1.3% | Apr 5, 2021 | The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course soluti... |
| CVE-2021-24185 | MEDIUM | 6.5 | 1.3% | Apr 5, 2021 | The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7... |
| CVE-2021-24184 | HIGH | 8.8 | 1.4% | Apr 5, 2021 | Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprot... |
| CVE-2021-24183 | MEDIUM | 6.5 | 1.7% | Apr 5, 2021 | The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress... |
| CVE-2021-24182 | MEDIUM | 6.5 | 1.7% | Apr 5, 2021 | The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution Wor... |
| CVE-2021-24181 | MEDIUM | 6.5 | 1.3% | Apr 5, 2021 | The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin ... |
| CVE-2021-24180 | MEDIUM | 5.4 | 0.6% | Apr 5, 2021 | Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Refle... |
| CVE-2021-24177 | MEDIUM | 5.4 | 0.9% | Apr 5, 2021 | In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint ... |
| CVE-2021-24176 | MEDIUM | 5.4 | 2.0% | Apr 5, 2021 | The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output ... |
| CVE-2021-24175 | CRITICAL | 9.8 | 14.5% | Apr 5, 2021 | The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious ac... |
| CVE-2021-24174 | HIGH | 8.1 | 3.2% | Apr 5, 2021 | The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in ... |
| CVE-2021-24173 | MEDIUM | 6.1 | 0.4% | Apr 5, 2021 | The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan... |
| CVE-2021-24172 | MEDIUM | 4.3 | 0.4% | Apr 5, 2021 | The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan... |
| CVE-2021-24171 | CRITICAL | 9.8 | 1.9% | Apr 5, 2021 | The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions su... |
| CVE-2021-24170 | HIGH | 7.5 | 4.8% | Apr 5, 2021 | The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than... |
| CVE-2021-24169 | MEDIUM | 6.1 | 10.3% | Apr 5, 2021 | This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order da... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now