2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-42248 | — | — | — | May 24, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42836. Reason: This candidate is a duplicate of ... |
| CVE-2021-42656 | MEDIUM | 5.4 | 0.7% | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. |
| CVE-2021-42655 | HIGH | 8.8 | 1.1% | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. |
| CVE-2021-42654 | CRITICAL | 9.8 | 1.6% | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be use... |
| CVE-2021-42659 | MEDIUM | 6.5 | 0.8% | May 24, 2022 | There is a buffer overflow vulnerability in the Web server httpd of the router in Tenda router devices such as Tenda AC9... |
| CVE-2021-32958 | MEDIUM | 5.5 | 0.2% | May 23, 2022 | Successful exploitation of this vulnerability on Claroty Secure Remote Access (SRA) Site versions 3.0 through 3.2 allows... |
| CVE-2021-42233 | MEDIUM | 5.4 | 0.8% | May 23, 2022 | The Simple Blog plugin in Wondercms 3.4.1 is vulnerable to stored cross-site scripting (XSS) vulnerability. When any use... |
| CVE-2021-32941 | CRITICAL | 9.8 | 13.3% | May 23, 2022 | Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based... |
| CVE-2021-32935 | CRITICAL | 9.8 | 1.7% | May 23, 2022 | The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which ... |
| CVE-2021-41714 | MEDIUM | 6.5 | 0.6% | May 23, 2022 | In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user... |
| CVE-2021-42586 | HIGH | 8.8 | 1.0% | May 23, 2022 | A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file. |
| CVE-2021-42585 | HIGH | 8.8 | 1.0% | May 23, 2022 | A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted ... |
| CVE-2021-41834 | MEDIUM | 6.5 | 0.5% | May 23, 2022 | JFrog Artifactory prior to version 7.28.0 and 6.23.38, is vulnerable to Broken Access Control, the copy functionality ca... |
| CVE-2021-36833 | MEDIUM | 4.8 | 0.5% | May 20, 2022 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ibericode's MC4WP plugin <=... |
| CVE-2021-39043 | MEDIUM | 5.4 | 0.4% | May 20, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to stored cross-site scripting. This vulnerabil... |
| CVE-2021-43729 | MEDIUM | 5.4 | 0.6% | May 20, 2022 | Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability... |
| CVE-2021-43728 | MEDIUM | 5.4 | 0.6% | May 20, 2022 | Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability... |
| CVE-2021-30028 | HIGH | 7.2 | 1.3% | May 20, 2022 | SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) ... |
| CVE-2021-34111 | CRITICAL | 9.8 | 2.5% | May 20, 2022 | Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.ph... |
| CVE-2021-32934 | HIGH | 7.5 | 0.6% | May 19, 2022 | The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not... |
| CVE-2021-45730 | MEDIUM | 4.9 | 0.5% | May 19, 2022 | JFrog Artifactory prior to 7.31.10, is vulnerable to Broken Access Control where a Project Admin is able to create, edit... |
| CVE-2021-37413 | CRITICAL | 9.8 | 1.8% | May 19, 2022 | GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated... |
| CVE-2021-26631 | HIGH | 7.5 | 1.0% | May 19, 2022 | Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote... |
| CVE-2021-26630 | CRITICAL | 9.8 | 0.7% | May 19, 2022 | Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbi... |
| CVE-2021-41938 | HIGH | 7.2 | 1.0% | May 19, 2022 | An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulne... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now