2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43505MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) ...
CVE-2021-34257HIGH8.8Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload t...
CVE-2021-20729MEDIUM6.1Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and p...
CVE-2021-43663HIGH7.5totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cl...
CVE-2021-43662MEDIUM6.5totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontroll...
CVE-2021-43661MEDIUM6.1totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v...
CVE-2021-46010HIGH8.8Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is...
CVE-2021-46009CRITICAL9.8In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, ad...
CVE-2021-46008HIGH8.8In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An atta...
CVE-2021-46007CRITICAL9.8totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command,...
CVE-2021-46006MEDIUM6.5In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function...
CVE-2021-43664HIGH8.1totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component pr...
CVE-2021-33523HIGH7.2MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new J...
CVE-2021-45900MEDIUM6.5Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configur...
CVE-2021-43142CRITICAL9.8An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.
CVE-2021-38362MEDIUM6.5In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint tha...
CVE-2021-33581HIGH7.2MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP servic...
CVE-2021-33208HIGH7.2The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a ...
CVE-2021-40645MEDIUM6.5An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataLi...
CVE-2021-40644MEDIUM6.5An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml.
CVE-2021-45031HIGH7.7A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate hi...
CVE-2021-44312HIGH8.8An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a C...
CVE-2021-44310MEDIUM4.8An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could...
CVE-2021-3456HIGH7.1An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients...
CVE-2021-39791MEDIUM5.5In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions,...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now