2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40902MEDIUM5.4flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index p...
CVE-2021-25116MEDIUM6.5The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX...
CVE-2021-37404CRITICAL9.8There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user wit...
CVE-2021-41641HIGH8.4Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the D...
CVE-2021-41750MEDIUM6.1A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inje...
CVE-2021-41749CRITICAL9.8In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Si...
CVE-2021-44266MEDIUM6.1GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
CVE-2021-41738HIGH8.8ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticate...
CVE-2021-41502MEDIUM5.4An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execut...
CVE-2021-41756CRITICAL9.8dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
CVE-2021-41755CRITICAL9.8dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.
CVE-2021-41754CRITICAL9.8dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.
CVE-2021-44582HIGH8.8A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remot...
CVE-2021-44117HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/si...
CVE-2021-42811MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows...
CVE-2021-27786CRITICAL9.8Cross-origin resource sharing (CORS) enables browsers to perform cross domain requests in a controlled manner. This requ...
CVE-2021-40961HIGH8.8CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variab...
CVE-2021-40668HIGH8.1The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability t...
CVE-2021-40610MEDIUM5.4Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.
CVE-2021-40592MEDIUM5.5GPAC version before commit 71460d72ec07df766dab0a4d52687529f3efcf0a (version v1.0.1 onwards) contains loop with unreacha...
CVE-2021-40589CRITICAL9.8ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fil...
CVE-2021-36710HIGH8.8ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management and having a low GDT addr...
CVE-2021-35532MEDIUM6.7A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerabil...
CVE-2021-35531MEDIUM6.7Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec...
CVE-2021-35530MEDIUM6.7A vulnerability in the application authentication and authorization mechanism in Hitachi Energy's TXpert Hub CoreTec 4, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now