2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40902 | MEDIUM | 5.4 | 0.4% | Jun 13, 2022 | flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index p... |
| CVE-2021-25116 | MEDIUM | 6.5 | 0.4% | Jun 13, 2022 | The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX... |
| CVE-2021-37404 | CRITICAL | 9.8 | 2.9% | Jun 13, 2022 | There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user wit... |
| CVE-2021-41641 | HIGH | 8.4 | 0.4% | Jun 12, 2022 | Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the D... |
| CVE-2021-41750 | MEDIUM | 6.1 | 1.0% | Jun 12, 2022 | A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inje... |
| CVE-2021-41749 | CRITICAL | 9.8 | 17.2% | Jun 12, 2022 | In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Si... |
| CVE-2021-44266 | MEDIUM | 6.1 | 1.0% | Jun 11, 2022 | GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter. |
| CVE-2021-41738 | HIGH | 8.8 | 1.7% | Jun 11, 2022 | ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticate... |
| CVE-2021-41502 | MEDIUM | 5.4 | 0.5% | Jun 11, 2022 | An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execut... |
| CVE-2021-41756 | CRITICAL | 9.8 | 1.2% | Jun 10, 2022 | dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php. |
| CVE-2021-41755 | CRITICAL | 9.8 | 1.2% | Jun 10, 2022 | dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php. |
| CVE-2021-41754 | CRITICAL | 9.8 | 1.2% | Jun 10, 2022 | dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php. |
| CVE-2021-44582 | HIGH | 8.8 | 1.4% | Jun 10, 2022 | A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remot... |
| CVE-2021-44117 | HIGH | 8.8 | 1.3% | Jun 10, 2022 | A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/si... |
| CVE-2021-42811 | MEDIUM | 6.5 | 0.5% | Jun 10, 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows... |
| CVE-2021-27786 | CRITICAL | 9.8 | 0.5% | Jun 9, 2022 | Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This requ... |
| CVE-2021-40961 | HIGH | 8.8 | 1.6% | Jun 9, 2022 | CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variab... |
| CVE-2021-40668 | HIGH | 8.1 | 1.1% | Jun 9, 2022 | The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability t... |
| CVE-2021-40610 | MEDIUM | 5.4 | 0.4% | Jun 9, 2022 | Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management. |
| CVE-2021-40592 | MEDIUM | 5.5 | 0.8% | Jun 8, 2022 | GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreacha... |
| CVE-2021-40589 | CRITICAL | 9.8 | 1.1% | Jun 8, 2022 | ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fil... |
| CVE-2021-36710 | HIGH | 8.8 | 0.3% | Jun 8, 2022 | ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management and having a low GDT addr... |
| CVE-2021-35532 | MEDIUM | 6.7 | 0.2% | Jun 7, 2022 | A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerabil... |
| CVE-2021-35531 | MEDIUM | 6.7 | 0.3% | Jun 7, 2022 | Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec... |
| CVE-2021-35530 | MEDIUM | 6.7 | 0.2% | Jun 7, 2022 | A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now