2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40241CRITICAL9.8xfig 3.2.7 is vulnerable to Buffer Overflow.
CVE-2021-40661HIGH7.5A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Adva...
CVE-2021-42777CRITICAL9.8Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrar...
CVE-2021-36898HIGH7.2Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-36864MEDIUM5.4Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4...
CVE-2021-38733CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
CVE-2021-38732CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
CVE-2021-38731CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
CVE-2021-38730CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
CVE-2021-38729CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
CVE-2021-38728MEDIUM6.1SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
CVE-2021-38217CRITICAL9.8SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
CVE-2021-36863MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3...
CVE-2021-36858MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
CVE-2021-38737CRITICAL9.8SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
CVE-2021-38736CRITICAL9.8SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
CVE-2021-38734CRITICAL9.8SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
CVE-2021-37782CRITICAL9.8Employee Record Management System v 1.2 is vulnerable to SQL Injection via editempprofile.php.
CVE-2021-37781MEDIUM5.4Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php.
CVE-2021-35388MEDIUM5.4Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
CVE-2021-35387HIGH8.8Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
CVE-2021-38399HIGH7.5Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow...
CVE-2021-38397CRITICAL10Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to unrestricted file uploads, which may all...
CVE-2021-38395CRITICAL9.8Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper neutralization of special eleme...
CVE-2021-36206MEDIUM6.1All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to by...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now