2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41074 | MEDIUM | 5.4 | 0.1% | Jan 12, 2026 | A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a ... |
| CVE-2021-47747 | HIGH | 8.8 | 0.6% | Dec 31, 2025 | meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php ... |
| CVE-2021-47745 | HIGH | 8.8 | 1.2% | Dec 31, 2025 | Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script... |
| CVE-2021-47744 | CRITICAL | 9.3 | 0.3% | Dec 31, 2025 | Cypress Solutions CTM-200/CTM-ONE 1.3.6 contains hard-coded credentials vulnerability in Linux distribution that exposes... |
| CVE-2021-47743 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in... |
| CVE-2021-47742 | HIGH | 8.8 | 0.2% | Dec 31, 2025 | Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users t... |
| CVE-2021-47741 | HIGH | 8.7 | 0.2% | Dec 31, 2025 | ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative ... |
| CVE-2021-47740 | HIGH | 7.5 | 0.4% | Dec 31, 2025 | KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session c... |
| CVE-2021-47726 | HIGH | 8.7 | 0.3% | Dec 31, 2025 | NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to acce... |
| CVE-2021-47725 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authentica... |
| CVE-2021-47739 | HIGH | 8.5 | 0.2% | Dec 23, 2025 | Epic Games Easy Anti-Cheat 4.0 contains an unquoted service path vulnerability that allows local non-privileged users to... |
| CVE-2021-47738 | MEDIUM | 5.4 | 0.2% | Dec 23, 2025 | CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious... |
| CVE-2021-47737 | MEDIUM | 5.4 | 0.2% | Dec 23, 2025 | CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in... |
| CVE-2021-47736 | HIGH | 8.6 | 0.9% | Dec 23, 2025 | CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality tha... |
| CVE-2021-47735 | HIGH | 8.8 | 0.8% | Dec 23, 2025 | CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject mal... |
| CVE-2021-47734 | HIGH | 8.6 | 0.7% | Dec 23, 2025 | CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP... |
| CVE-2021-47733 | MEDIUM | 6.1 | 0.2% | Dec 23, 2025 | CMSimple 5.4 contains a cross-site scripting vulnerability that allows attackers to bypass input filtering by using HTML... |
| CVE-2021-47732 | MEDIUM | 6.1 | 0.2% | Dec 23, 2025 | CMSimple 5.2 contains a stored cross-site scripting vulnerability in the Filebrowser External input field that allows at... |
| CVE-2021-47722 | MEDIUM | 5.1 | 0.2% | Dec 23, 2025 | Zucchetti Axess CLOKI Access Control 1.64 contains a cross-site request forgery vulnerability that allows attackers to m... |
| CVE-2021-47721 | HIGH | 8.8 | 0.4% | Dec 23, 2025 | Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other proje... |
| CVE-2021-47720 | HIGH | 8.7 | 0.3% | Dec 23, 2025 | Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate datab... |
| CVE-2021-47716 | MEDIUM | 5.4 | 0.2% | Dec 23, 2025 | Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject ma... |
| CVE-2021-47715 | MEDIUM | 6.9 | 0.3% | Dec 22, 2025 | Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remo... |
| CVE-2021-47714 | MEDIUM | 5.5 | 0.2% | Dec 22, 2025 | Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL i... |
| CVE-2021-47713 | HIGH | 8.7 | 0.4% | Dec 22, 2025 | Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now