2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-44096 | CRITICAL | 9.8 | 1.2% | Jun 2, 2022 | EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action... |
| CVE-2021-44095 | CRITICAL | 9.8 | 2.2% | Jun 2, 2022 | A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a ... |
| CVE-2021-44080 | HIGH | 7.2 | 23.7% | Jun 2, 2022 | A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged... |
| CVE-2021-43512 | MEDIUM | 5.5 | 0.2% | Jun 2, 2022 | An issue was discovered in FlightRadar24 v8.9.0, v8.10.0, v8.10.2, v8.10.3, v8.10.4 for Android, allows attackers to cau... |
| CVE-2021-43308 | HIGH | 7.5 | 1.0% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package,... |
| CVE-2021-43307 | HIGH | 7.5 | 1.5% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an at... |
| CVE-2021-43306 | HIGH | 7.5 | 1.3% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when ... |
| CVE-2021-42872 | CRITICAL | 9.8 | 8.2% | Jun 2, 2022 | TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code... |
| CVE-2021-42204 | HIGH | 7.8 | 1.2% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetBits() locate... |
| CVE-2021-42203 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-use-after-free exists in the function swf_FontExtract_Defin... |
| CVE-2021-42202 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_DeleteFilter... |
| CVE-2021-42201 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function swf_GetD64() located... |
| CVE-2021-42200 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function main() located i... |
| CVE-2021-42199 | HIGH | 7.8 | 1.0% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap buffer overflow exists in the function swf_FontExtract_Defi... |
| CVE-2021-42198 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function swf_GetBits() lo... |
| CVE-2021-42197 | HIGH | 7.8 | 1.1% | Jun 2, 2022 | An issue was discovered in swftools through 20201222 through a memory leak in the swftools when swfdump is used. It allo... |
| CVE-2021-42196 | MEDIUM | 5.5 | 0.7% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A NULL pointer dereference exists in the function traits_parse() l... |
| CVE-2021-42195 | HIGH | 7.8 | 0.9% | Jun 2, 2022 | An issue was discovered in swftools through 20201222. A heap-buffer-overflow exists in the function handleEditText() loc... |
| CVE-2021-40186 | HIGH | 7.5 | 1.1% | Jun 2, 2022 | The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, fo... |
| CVE-2021-3676 | — | — | — | Jun 2, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-36890 | MEDIUM | 4.3 | 0.4% | Jun 2, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress. |
| CVE-2021-36866 | MEDIUM | 4.8 | 0.5% | Jun 2, 2022 | Authenticated (author or higher role) Stored Cross-Site Scripting (XSS) vulnerability in Fatcat Apps Easy Pricing Tables... |
| CVE-2021-34084 | CRITICAL | 9.8 | 3.0% | Jun 2, 2022 | OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to ex... |
| CVE-2021-34083 | HIGH | 8.1 | 1.9% | Jun 2, 2022 | Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON... |
| CVE-2021-34082 | CRITICAL | 9.8 | 4.9% | Jun 2, 2022 | OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now