2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25031MEDIUM6.1The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7...
CVE-2021-25028MEDIUM6.1The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirec...
CVE-2021-25017MEDIUM6.1The Tutor LMS WordPress plugin before 1.9.12 does not escape the search parameter before outputting it back in an attrib...
CVE-2021-25015MEDIUM6.1The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the hi...
CVE-2021-25013MEDIUM6.5The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJA...
CVE-2021-25008MEDIUM6.1The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it b...
CVE-2021-24989MEDIUM6.5The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure tha...
CVE-2021-24985MEDIUM6.1The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type pa...
CVE-2021-24976MEDIUM6.1The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it ...
CVE-2021-24974MEDIUM5.4The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some o...
CVE-2021-24968MEDIUM5.7The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq ...
CVE-2021-24965MEDIUM5.4The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_...
CVE-2021-24923MEDIUM6.1The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape t...
CVE-2021-24733MEDIUM4.3The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view othe...
CVE-2021-24694MEDIUM5.4The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perfor...
CVE-2021-24423MEDIUM4.8The UpdraftPlus WordPress Backup Plugin WordPress plugin before 1.6.59 does not sanitise its updraft_service settings, a...
CVE-2021-45380MEDIUM6.1AppCMS 2.0.101 has a XSS injection vulnerability in \templates\m\inc_head.php
CVE-2021-4103MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.
CVE-2021-4172MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2021-46313MEDIUM5.5The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned...
CVE-2021-46311MEDIUM5.5A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vr...
CVE-2021-46244MEDIUM6.5A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This ...
CVE-2021-46243MEDIUM6.5An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at ...
CVE-2021-46240MEDIUM5.5A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager...
CVE-2021-46239MEDIUM5.5The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now