2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41635 | HIGH | 8.8 | 1.9% | Jun 24, 2022 | When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse... |
| CVE-2021-41634 | MEDIUM | 5.3 | 0.9% | Jun 24, 2022 | A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames. |
| CVE-2021-34604 | — | — | — | Jun 24, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. It... |
| CVE-2021-46824 | MEDIUM | 5.4 | 0.9% | Jun 23, 2022 | Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter ... |
| CVE-2021-41432 | MEDIUM | 5.4 | 1.7% | Jun 23, 2022 | A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaS... |
| CVE-2021-40956 | HIGH | 7.5 | 1.0% | Jun 23, 2022 | LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obta... |
| CVE-2021-40955 | HIGH | 7.2 | 0.9% | Jun 23, 2022 | SQL injection exists in LaiKetui v3.5.0 the background administrator list. |
| CVE-2021-40954 | CRITICAL | 9.8 | 1.6% | Jun 23, 2022 | Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary cod... |
| CVE-2021-29055 | MEDIUM | 6.1 | 0.8% | Jun 23, 2022 | Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname paramete... |
| CVE-2021-26638 | CRITICAL | 9.8 | 3.4% | Jun 23, 2022 | Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and inform... |
| CVE-2021-26637 | CRITICAL | 9.8 | 1.7% | Jun 23, 2022 | There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-... |
| CVE-2021-26636 | CRITICAL | 9.6 | 1.4% | Jun 23, 2022 | Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to in... |
| CVE-2021-40511 | HIGH | 7.5 | 0.9% | Jun 21, 2022 | OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service. |
| CVE-2021-40510 | HIGH | 7.5 | 1.2% | Jun 21, 2022 | XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs. |
| CVE-2021-36761 | MEDIUM | 5.3 | 1.1% | Jun 21, 2022 | The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF. |
| CVE-2021-39006 | MEDIUM | 5.3 | 0.8% | Jun 21, 2022 | IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best ... |
| CVE-2021-41924 | MEDIUM | 6.1 | 0.6% | Jun 21, 2022 | Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2021-41683 | HIGH | 7.8 | 0.7% | Jun 20, 2022 | There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0 |
| CVE-2021-41682 | HIGH | 7.8 | 0.7% | Jun 20, 2022 | There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.... |
| CVE-2021-25121 | MEDIUM | 6.5 | 1.2% | Jun 20, 2022 | The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of lon... |
| CVE-2021-25104 | MEDIUM | 6.1 | 1.4% | Jun 20, 2022 | The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is ac... |
| CVE-2021-25088 | MEDIUM | 4.8 | 0.6% | Jun 20, 2022 | The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug... |
| CVE-2021-45918 | HIGH | 7.5 | 1.4% | Jun 20, 2022 | NHI’s health insurance web service component has insufficient validation for input string length, which can result in he... |
| CVE-2021-46823 | MEDIUM | 6.5 | 1.7% | Jun 18, 2022 | python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions,... |
| CVE-2021-46822 | MEDIUM | 5.5 | 1.0% | Jun 18, 2022 | The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now