2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27442MEDIUM6.1The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated...
CVE-2021-23267HIGH8.8Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2021-23266MEDIUM4.3An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual mess...
CVE-2021-23265MEDIUM4.3A logged-in and authenticated user with a Reviewer Role may lock a content item.
CVE-2021-33318CRITICAL9.8An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below...
CVE-2021-25119HIGH7.2The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating t...
CVE-2021-42966Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-42897CRITICAL9.8A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[...
CVE-2021-42870HIGH7.5ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request.
CVE-2021-41927Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-41965HIGH8.8A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue ...
CVE-2021-33013HIGH7.5mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
CVE-2021-33009HIGH7.5mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file s...
CVE-2021-33005HIGH7.5mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary ...
CVE-2021-27505HIGH7.5mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing informa...
CVE-2021-46789HIGH7.5Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.
CVE-2021-46788HIGH7.5Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability ma...
CVE-2021-46787HIGH7.5The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may caus...
CVE-2021-46786CRITICAL9.8The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation...
CVE-2021-46785MEDIUM5.3The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique d...
CVE-2021-22275HIGH8.6Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to st...
CVE-2021-42969HIGH8.8Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a ...
CVE-2021-42967CRITICAL9.8Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus a...
CVE-2021-27777HIGH7.5XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input...
CVE-2021-27773MEDIUM4.3This vulnerability allows users to execute a clickjacking attack in the meeting's chat.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now