2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27442 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated... |
| CVE-2021-23267 | HIGH | 8.8 | 0.8% | May 16, 2022 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat... |
| CVE-2021-23266 | MEDIUM | 4.3 | 0.5% | May 16, 2022 | An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual mess... |
| CVE-2021-23265 | MEDIUM | 4.3 | 0.5% | May 16, 2022 | A logged-in and authenticated user with a Reviewer Role may lock a content item. |
| CVE-2021-33318 | CRITICAL | 9.8 | 1.9% | May 16, 2022 | An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below... |
| CVE-2021-25119 | HIGH | 7.2 | 1.4% | May 16, 2022 | The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating t... |
| CVE-2021-42966 | — | — | — | May 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-42897 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[... |
| CVE-2021-42870 | HIGH | 7.5 | 1.0% | May 16, 2022 | ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request. |
| CVE-2021-41927 | — | — | — | May 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-41965 | HIGH | 8.8 | 1.1% | May 15, 2022 | A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue ... |
| CVE-2021-33013 | HIGH | 7.5 | 0.8% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. |
| CVE-2021-33009 | HIGH | 7.5 | 1.1% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file s... |
| CVE-2021-33005 | HIGH | 7.5 | 1.4% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary ... |
| CVE-2021-27505 | HIGH | 7.5 | 1.0% | May 13, 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing informa... |
| CVE-2021-46789 | HIGH | 7.5 | 0.6% | May 13, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability. |
| CVE-2021-46788 | HIGH | 7.5 | 0.5% | May 13, 2022 | Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability ma... |
| CVE-2021-46787 | HIGH | 7.5 | 0.7% | May 13, 2022 | The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may caus... |
| CVE-2021-46786 | CRITICAL | 9.8 | 0.7% | May 13, 2022 | The audio module has a vulnerability in verifying the parameters passed by the application space.Successful exploitation... |
| CVE-2021-46785 | MEDIUM | 5.3 | 0.5% | May 13, 2022 | The Property module has a vulnerability in permission control.This vulnerability can be exploited to obtain the unique d... |
| CVE-2021-22275 | HIGH | 8.6 | 0.9% | May 13, 2022 | Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to st... |
| CVE-2021-42969 | HIGH | 8.8 | 1.8% | May 13, 2022 | Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a ... |
| CVE-2021-42967 | CRITICAL | 9.8 | 1.0% | May 13, 2022 | Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus a... |
| CVE-2021-27777 | HIGH | 7.5 | 0.8% | May 12, 2022 | XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input... |
| CVE-2021-27773 | MEDIUM | 4.3 | 0.4% | May 12, 2022 | This vulnerability allows users to execute a clickjacking attack in the meeting's chat. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now