2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24168 | MEDIUM | 5.4 | 0.6% | Apr 5, 2021 | The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subje... |
| CVE-2021-24167 | HIGH | 7.5 | 1.4% | Apr 5, 2021 | When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send ... |
| CVE-2021-24166 | MEDIUM | 5.4 | 0.5% | Apr 5, 2021 | The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPre... |
| CVE-2021-24165 | MEDIUM | 6.1 | 1.6% | Apr 5, 2021 | In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable ... |
| CVE-2021-24164 | MEDIUM | 4.3 | 0.9% | Apr 5, 2021 | In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri... |
| CVE-2021-24163 | HIGH | 8.8 | 1.4% | Apr 5, 2021 | The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it ha... |
| CVE-2021-24162 | HIGH | 8.8 | 0.8% | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini... |
| CVE-2021-24161 | HIGH | 8.8 | 1.2% | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini... |
| CVE-2021-24160 | HIGH | 8.8 | 8.4% | Apr 5, 2021 | In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing ma... |
| CVE-2021-24159 | HIGH | 8.8 | 0.6% | Apr 5, 2021 | Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a reques... |
| CVE-2021-24158 | MEDIUM | 6.5 | 0.9% | Apr 5, 2021 | Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f... |
| CVE-2021-24157 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no che... |
| CVE-2021-24156 | MEDIUM | 5.4 | 0.7% | Apr 5, 2021 | Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inj... |
| CVE-2021-24155 | HIGH | 7.2 | 83.7% | Apr 5, 2021 | The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported fi... |
| CVE-2021-24154 | MEDIUM | 4.9 | 1.1% | Apr 5, 2021 | The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f... |
| CVE-2021-24153 | MEDIUM | 5.4 | 1.1% | Apr 5, 2021 | A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had bui... |
| CVE-2021-24152 | MEDIUM | 6.1 | 0.7% | Apr 5, 2021 | The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting. |
| CVE-2021-24150 | HIGH | 7.5 | 4.4% | Apr 5, 2021 | The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full... |
| CVE-2021-30109 | MEDIUM | 6.1 | 1.1% | Apr 5, 2021 | Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads t... |
| CVE-2021-30058 | MEDIUM | 6.1 | 1.0% | Apr 5, 2021 | Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script i... |
| CVE-2021-30057 | MEDIUM | 4.8 | 0.7% | Apr 5, 2021 | A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/re... |
| CVE-2021-30056 | MEDIUM | 5.4 | 0.6% | Apr 5, 2021 | Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web scr... |
| CVE-2021-30055 | HIGH | 8.8 | 1.6% | Apr 5, 2021 | A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver componen... |
| CVE-2021-29996 | CRITICAL | 9.6 | 2.8% | Apr 5, 2021 | Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by... |
| CVE-2021-29261 | HIGH | 7.8 | 1.2% | Apr 5, 2021 | The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now