2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28789HIGH7.8The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbit...
CVE-2021-28145MEDIUM5.4Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted su...
CVE-2021-26216MEDIUM4.3SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditFolder.php.
CVE-2021-26215MEDIUM4.3SeedDMS 5.1.x is affected by cross-site request forgery (CSRF) in out.EditDocument.php.
CVE-2021-27306HIGH7.5An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users...
CVE-2021-26935HIGH7.5In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers S...
CVE-2021-24149HIGH8.8Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[...
CVE-2021-24148CRITICAL9.8A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign...
CVE-2021-24147MEDIUM5.4Unvalidated input and lack of output encoding in the Modern Events Calendar Lite WordPress plugin, versions before 5.16....
CVE-2021-24146HIGH7.5Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper...
CVE-2021-24145HIGH7.2Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly chec...
CVE-2021-24144HIGH7.8Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha...
CVE-2021-24143HIGH8.8Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, ...
CVE-2021-24142HIGH7.2Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise ...
CVE-2021-24141HIGH7.2Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high pr...
CVE-2021-24140HIGH7.2Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin...
CVE-2021-24139CRITICAL9.8Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions before 1.5.55, leads to SQL inje...
CVE-2021-24138MEDIUM5.5Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para...
CVE-2021-24137HIGH8.8Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Post...
CVE-2021-24136MEDIUM5.4Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead t...
CVE-2021-24135MEDIUM6.1Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead t...
CVE-2021-24134MEDIUM4.8Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lea...
CVE-2021-24133MEDIUM4.3Lack of CSRF checks in the ActiveCampaign WordPress plugin, versions before 8.0.2, on its Settings form, which could all...
CVE-2021-24132HIGH8.8The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functio...
CVE-2021-24131HIGH7.2Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now