2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28789 | HIGH | 7.8 | 1.7% | Mar 18, 2021 | The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbit... |
| CVE-2021-28145 | MEDIUM | 5.4 | 0.9% | Mar 18, 2021 | Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted su... |
| CVE-2021-26216 | MEDIUM | 4.3 | 0.5% | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php. |
| CVE-2021-26215 | MEDIUM | 4.3 | 0.5% | Mar 18, 2021 | SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php. |
| CVE-2021-27306 | HIGH | 7.5 | 1.8% | Mar 18, 2021 | An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users... |
| CVE-2021-26935 | HIGH | 7.5 | 2.3% | Mar 18, 2021 | In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers S... |
| CVE-2021-24149 | HIGH | 8.8 | 1.5% | Mar 18, 2021 | Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[... |
| CVE-2021-24148 | CRITICAL | 9.8 | 3.4% | Mar 18, 2021 | A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign... |
| CVE-2021-24147 | MEDIUM | 5.4 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.... |
| CVE-2021-24146 | HIGH | 7.5 | 31.0% | Mar 18, 2021 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper... |
| CVE-2021-24145 | HIGH | 7.2 | 88.2% | Mar 18, 2021 | Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly chec... |
| CVE-2021-24144 | HIGH | 7.8 | 1.2% | Mar 18, 2021 | Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha... |
| CVE-2021-24143 | HIGH | 8.8 | 1.3% | Mar 18, 2021 | Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, ... |
| CVE-2021-24142 | HIGH | 7.2 | 1.2% | Mar 18, 2021 | Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise ... |
| CVE-2021-24141 | HIGH | 7.2 | 1.2% | Mar 18, 2021 | Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high pr... |
| CVE-2021-24140 | HIGH | 7.2 | 1.2% | Mar 18, 2021 | Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin... |
| CVE-2021-24139 | CRITICAL | 9.8 | 5.4% | Mar 18, 2021 | Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje... |
| CVE-2021-24138 | MEDIUM | 5.5 | 1.2% | Mar 18, 2021 | Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para... |
| CVE-2021-24137 | HIGH | 8.8 | 1.5% | Mar 18, 2021 | Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Post... |
| CVE-2021-24136 | MEDIUM | 5.4 | 0.8% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t... |
| CVE-2021-24135 | MEDIUM | 6.1 | 1.1% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead t... |
| CVE-2021-24134 | MEDIUM | 4.8 | 0.7% | Mar 18, 2021 | Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lea... |
| CVE-2021-24133 | MEDIUM | 4.3 | 0.5% | Mar 18, 2021 | Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could all... |
| CVE-2021-24132 | HIGH | 8.8 | 2.6% | Mar 18, 2021 | The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functio... |
| CVE-2021-24131 | HIGH | 7.2 | 1.4% | Mar 18, 2021 | Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now