2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40903 | CRITICAL | 9.8 | 4.4% | Jun 17, 2022 | A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flas... |
| CVE-2021-45026 | MEDIUM | 6.1 | 1.5% | Jun 17, 2022 | ASG technologies ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2021-45025 | HIGH | 7.5 | 0.7% | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to C... |
| CVE-2021-45024 | CRITICAL | 9.8 | 1.3% | Jun 17, 2022 | ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to X... |
| CVE-2021-41490 | HIGH | 7.5 | 0.9% | Jun 17, 2022 | Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior. |
| CVE-2021-41408 | CRITICAL | 9.8 | 1.1% | Jun 17, 2022 | VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter. |
| CVE-2021-46820 | HIGH | 8.1 | 0.7% | Jun 16, 2022 | Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho... |
| CVE-2021-37764 | HIGH | 8.1 | 0.7% | Jun 16, 2022 | Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho... |
| CVE-2021-36609 | MEDIUM | 5.4 | 0.4% | Jun 16, 2022 | Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php. |
| CVE-2021-36608 | MEDIUM | 5.4 | 0.4% | Jun 16, 2022 | Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php. |
| CVE-2021-33295 | MEDIUM | 5.4 | 0.8% | Jun 16, 2022 | Cross Site Scripting (XSS) vulnerability in Joplin Desktop App before 1.8.5 allows attackers to execute aribrary code du... |
| CVE-2021-41487 | CRITICAL | 9.8 | 1.6% | Jun 16, 2022 | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. |
| CVE-2021-36827 | MEDIUM | 4.8 | 0.5% | Jun 16, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saturday Drive's Ninja Forms Contact Form plugin <= 3.... |
| CVE-2021-41421 | MEDIUM | 4.8 | 0.5% | Jun 16, 2022 | A PHP code injection vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker to gain RCE through the Maia... |
| CVE-2021-41420 | MEDIUM | 5.4 | 0.7% | Jun 16, 2022 | A stored XSS vulnerability in MaianAffiliate v.1.0 allows an authenticated attacker for arbitrary JavaScript code execut... |
| CVE-2021-3675 | HIGH | 7.1 | 0.3% | Jun 16, 2022 | Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized ... |
| CVE-2021-41654 | CRITICAL | 9.8 | 1.0% | Jun 16, 2022 | SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the ... |
| CVE-2021-41458 | MEDIUM | 5.5 | 0.6% | Jun 16, 2022 | In GPAC MP4Box v1.1.0, there is a stack buffer overflow at src/utils/error.c:1769 which leads to a denial of service vul... |
| CVE-2021-41411 | CRITICAL | 9.8 | 1.2% | Jun 16, 2022 | drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator cla... |
| CVE-2021-41402 | HIGH | 8.8 | 1.3% | Jun 16, 2022 | flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP co... |
| CVE-2021-41403 | CRITICAL | 9.8 | 17.2% | Jun 15, 2022 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. |
| CVE-2021-43755 | HIGH | 7.8 | 1.9% | Jun 15, 2022 | Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerab... |
| CVE-2021-42735 | HIGH | 7.8 | 2.0% | Jun 15, 2022 | Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer v... |
| CVE-2021-41418 | CRITICAL | 9.8 | 0.9% | Jun 15, 2022 | AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' acces... |
| CVE-2021-41415 | MEDIUM | 6.1 | 0.6% | Jun 15, 2022 | Subscription-Manager v1.0 /main.js has a cross-site scripting (XSS) vulnerability in the machineDetail parameter. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now