2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41635HIGH8.8When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse...
CVE-2021-41634MEDIUM5.3A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
CVE-2021-34604Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. It...
CVE-2021-46824MEDIUM5.4Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter ...
CVE-2021-41432MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in FlatPress 1.2.1 that allows for arbitrary execution of JavaS...
CVE-2021-40956HIGH7.5LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obta...
CVE-2021-40955HIGH7.2SQL injection exists in LaiKetui v3.5.0 the background administrator list.
CVE-2021-40954CRITICAL9.8Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary cod...
CVE-2021-29055MEDIUM6.1Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname paramete...
CVE-2021-26638CRITICAL9.8Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and inform...
CVE-2021-26637CRITICAL9.8There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-...
CVE-2021-26636CRITICAL9.6Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to in...
CVE-2021-40511HIGH7.5OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
CVE-2021-40510HIGH7.5XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
CVE-2021-36761MEDIUM5.3The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
CVE-2021-39006MEDIUM5.3IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best ...
CVE-2021-41924MEDIUM6.1Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-41683HIGH7.8There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0
CVE-2021-41682HIGH7.8There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4....
CVE-2021-25121MEDIUM6.5The Rating by BestWebSoft WordPress plugin before 1.6 does not validate the submitted rating, allowing submission of lon...
CVE-2021-25104MEDIUM6.1The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is ac...
CVE-2021-25088MEDIUM4.8The XML Sitemaps WordPress plugin before 4.1.3 does not sanitise and escape a settings before outputting it in the Debug...
CVE-2021-45918HIGH7.5NHI’s health insurance web service component has insufficient validation for input string length, which can result in he...
CVE-2021-46823MEDIUM6.5python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions,...
CVE-2021-46822MEDIUM5.5The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now