2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24207MEDIUM4.3By default, the WP Page Builder WordPress plugin before 1.2.4 allows subscriber-level users to edit and make changes to ...
CVE-2021-24206MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) ac...
CVE-2021-24205MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) acce...
CVE-2021-24204MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) ac...
CVE-2021-24203MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accept...
CVE-2021-24202MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accept...
CVE-2021-24201MEDIUM5.4In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accept...
CVE-2021-24196MEDIUM5.4The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page a...
CVE-2021-24187MEDIUM5.4The setting page of the SEO Redirection Plugin - 301 Redirect Manager WordPress plugin before 6.4 is vulnerable to refle...
CVE-2021-24186MEDIUM6.5The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course soluti...
CVE-2021-24185MEDIUM6.5The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7...
CVE-2021-24184HIGH8.8Several AJAX endpoints in the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 were unprot...
CVE-2021-24183MEDIUM6.5The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPress...
CVE-2021-24182MEDIUM6.5The tutor_quiz_builder_get_answers_by_question AJAX action from the Tutor LMS – eLearning and online course solution Wor...
CVE-2021-24181MEDIUM6.5The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin ...
CVE-2021-24180MEDIUM5.4Unvalidated input and lack of output encoding within the Related Posts for WordPress plugin before 2.0.4 lead to a Refle...
CVE-2021-24177MEDIUM5.4In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint ...
CVE-2021-24176MEDIUM5.4The JH 404 Logger WordPress plugin through 1.1 doesn't sanitise the referer and path of 404 pages, when they are output ...
CVE-2021-24175CRITICAL9.8The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious ac...
CVE-2021-24174HIGH8.1The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in ...
CVE-2021-24173MEDIUM6.1The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan...
CVE-2021-24172MEDIUM4.3The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwan...
CVE-2021-24171CRITICAL9.8The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions su...
CVE-2021-24170HIGH7.5The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than...
CVE-2021-24169MEDIUM6.1This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order da...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now