2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42248Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42836. Reason: This candidate is a duplicate of ...
CVE-2021-42656MEDIUM5.4SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-42655HIGH8.8SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
CVE-2021-42654CRITICAL9.8SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be use...
CVE-2021-42659MEDIUM6.5There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9...
CVE-2021-32958MEDIUM5.5Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows...
CVE-2021-42233MEDIUM5.4The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any use...
CVE-2021-32941CRITICAL9.8Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based...
CVE-2021-32935CRITICAL9.8The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which ...
CVE-2021-41714MEDIUM6.5In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user...
CVE-2021-42586HIGH8.8A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
CVE-2021-42585HIGH8.8A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted ...
CVE-2021-41834MEDIUM6.5JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality ca...
CVE-2021-36833MEDIUM4.8Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <=...
CVE-2021-39043MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerabil...
CVE-2021-43729MEDIUM5.4Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability...
CVE-2021-43728MEDIUM5.4Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability...
CVE-2021-30028HIGH7.2SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) ...
CVE-2021-34111CRITICAL9.8Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.ph...
CVE-2021-32934HIGH7.5The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not...
CVE-2021-45730MEDIUM4.9JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit...
CVE-2021-37413CRITICAL9.8GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated...
CVE-2021-26631HIGH7.5Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote...
CVE-2021-26630CRITICAL9.8Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbi...
CVE-2021-41938HIGH7.2An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulne...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now