2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24168MEDIUM5.4The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subje...
CVE-2021-24167HIGH7.5When visiting a site running Web-Stat < 1.4.0, the "wts_web_stat_load_init" function used the visitor’s browser to send ...
CVE-2021-24166MEDIUM5.4The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPre...
CVE-2021-24165MEDIUM6.1In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable ...
CVE-2021-24164MEDIUM4.3In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to tri...
CVE-2021-24163HIGH8.8The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it ha...
CVE-2021-24162HIGH8.8In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini...
CVE-2021-24161HIGH8.8In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an admini...
CVE-2021-24160HIGH8.8In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing ma...
CVE-2021-24159HIGH8.8Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a reques...
CVE-2021-24158MEDIUM6.5Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders f...
CVE-2021-24157MEDIUM5.4Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no che...
CVE-2021-24156MEDIUM5.4Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inj...
CVE-2021-24155HIGH7.2The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported fi...
CVE-2021-24154MEDIUM4.9The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f...
CVE-2021-24153MEDIUM5.4A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had bui...
CVE-2021-24152MEDIUM6.1The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.
CVE-2021-24150HIGH7.5The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full...
CVE-2021-30109MEDIUM6.1Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads t...
CVE-2021-30058MEDIUM6.1Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script i...
CVE-2021-30057MEDIUM4.8A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in "/re...
CVE-2021-30056MEDIUM5.4Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web scr...
CVE-2021-30055HIGH8.8A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver componen...
CVE-2021-29996CRITICAL9.6Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by...
CVE-2021-29261HIGH7.8The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now