2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41074MEDIUM5.4A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a ...
CVE-2021-47747HIGH8.8meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php ...
CVE-2021-47745HIGH8.8Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script...
CVE-2021-47744CRITICAL9.3Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes...
CVE-2021-47743MEDIUM6.1COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in...
CVE-2021-47742HIGH8.8Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users t...
CVE-2021-47741HIGH8.7ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative ...
CVE-2021-47740HIGH7.5KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session c...
CVE-2021-47726HIGH8.7NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to acce...
CVE-2021-47725MEDIUM5.4STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authentica...
CVE-2021-47739HIGH8.5Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to...
CVE-2021-47738MEDIUM5.4CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious...
CVE-2021-47737MEDIUM5.4CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in...
CVE-2021-47736HIGH8.6CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality tha...
CVE-2021-47735HIGH8.8CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject mal...
CVE-2021-47734HIGH8.6CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP...
CVE-2021-47733MEDIUM6.1CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML...
CVE-2021-47732MEDIUM6.1CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows at...
CVE-2021-47722MEDIUM5.1Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to m...
CVE-2021-47721HIGH8.8Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other proje...
CVE-2021-47720HIGH8.7Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate datab...
CVE-2021-47716MEDIUM5.4Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject ma...
CVE-2021-47715MEDIUM6.9Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remo...
CVE-2021-47714MEDIUM5.5Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL i...
CVE-2021-47713HIGH8.7Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafti...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now