2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21924MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21923MEDIUM4.9A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21922MEDIUM6.5A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21921MEDIUM4.9A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21920MEDIUM4.9A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21919MEDIUM4.9A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21918MEDIUM4.9A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger ...
CVE-2021-21908MEDIUM6.5Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attemp...
CVE-2021-21907MEDIUM4.9A directory traversal vulnerability exists in the CMA CLI getenv command functionality of Garrett Metal Detectors’ iC Mo...
CVE-2021-21896MEDIUM6.5A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 ...
CVE-2021-21886MEDIUM4.3A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8...
CVE-2021-21878MEDIUM4.9A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix Prem...
CVE-2021-45267MEDIUM5.5An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a...
CVE-2021-45263MEDIUM5.5An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmen...
CVE-2021-45262MEDIUM5.5An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault...
CVE-2021-45261MEDIUM5.5An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service...
CVE-2021-45260MEDIUM5.5A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentat...
CVE-2021-43158MEDIUM4.3In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to rem...
CVE-2021-43156MEDIUM6.5In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete a...
CVE-2021-45259MEDIUM5.5An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segment...
CVE-2021-45258MEDIUM5.5A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation...
CVE-2021-45257MEDIUM5.5An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.
CVE-2021-45256MEDIUM5.5A Null Pointer Dereference vulnerability existfs in nasm 2.16rc0 via asm/preproc.c.
CVE-2021-39013MEDIUM6.5IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive in...
CVE-2021-40836MEDIUM5.5A vulnerability affecting F-Secure antivirus engine was discovered whereby scanning MS outlook .pst files can lead to de...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now