2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25031 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7... |
| CVE-2021-25028 | MEDIUM | 6.1 | 1.9% | Jan 24, 2022 | The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirec... |
| CVE-2021-25017 | MEDIUM | 6.1 | 1.0% | Jan 24, 2022 | The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attrib... |
| CVE-2021-25015 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the hi... |
| CVE-2021-25013 | MEDIUM | 6.5 | 0.4% | Jan 24, 2022 | The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA... |
| CVE-2021-25008 | MEDIUM | 6.1 | 2.3% | Jan 24, 2022 | The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it b... |
| CVE-2021-24989 | MEDIUM | 6.5 | 0.5% | Jan 24, 2022 | The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure tha... |
| CVE-2021-24985 | MEDIUM | 6.1 | 1.1% | Jan 24, 2022 | The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type pa... |
| CVE-2021-24976 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it ... |
| CVE-2021-24974 | MEDIUM | 5.4 | 0.6% | Jan 24, 2022 | The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some o... |
| CVE-2021-24968 | MEDIUM | 5.7 | 0.4% | Jan 24, 2022 | The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq ... |
| CVE-2021-24965 | MEDIUM | 5.4 | 0.6% | Jan 24, 2022 | The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_... |
| CVE-2021-24923 | MEDIUM | 6.1 | 0.8% | Jan 24, 2022 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape t... |
| CVE-2021-24733 | MEDIUM | 4.3 | 0.8% | Jan 24, 2022 | The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view othe... |
| CVE-2021-24694 | MEDIUM | 5.4 | 0.6% | Jan 24, 2022 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perfor... |
| CVE-2021-24423 | MEDIUM | 4.8 | 0.6% | Jan 24, 2022 | The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a... |
| CVE-2021-45380 | MEDIUM | 6.1 | 2.5% | Jan 23, 2022 | AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php |
| CVE-2021-4103 | MEDIUM | 5.4 | 0.7% | Jan 23, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34. |
| CVE-2021-4172 | MEDIUM | 5.4 | 0.6% | Jan 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. |
| CVE-2021-46313 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned... |
| CVE-2021-46311 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vr... |
| CVE-2021-46244 | MEDIUM | 6.5 | 1.0% | Jan 21, 2022 | A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This ... |
| CVE-2021-46243 | MEDIUM | 6.5 | 1.0% | Jan 21, 2022 | An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at ... |
| CVE-2021-46240 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager... |
| CVE-2021-46239 | MEDIUM | 5.5 | 0.6% | Jan 21, 2022 | The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now