2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43505 | MEDIUM | 5.4 | 0.5% | Mar 31, 2022 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) ... |
| CVE-2021-34257 | HIGH | 8.8 | 1.7% | Mar 31, 2022 | Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload t... |
| CVE-2021-20729 | MEDIUM | 6.1 | 2.8% | Mar 31, 2022 | Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and p... |
| CVE-2021-43663 | HIGH | 7.5 | 1.0% | Mar 31, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cl... |
| CVE-2021-43662 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue which causes uncontroll... |
| CVE-2021-43661 | MEDIUM | 6.1 | 0.6% | Mar 31, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v... |
| CVE-2021-46010 | HIGH | 8.8 | 1.6% | Mar 30, 2022 | Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is... |
| CVE-2021-46009 | CRITICAL | 9.8 | 15.2% | Mar 30, 2022 | In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, ad... |
| CVE-2021-46008 | HIGH | 8.8 | 1.2% | Mar 30, 2022 | In totolink a3100r V5.9c.4577, the hard-coded telnet password can be discovered from official released firmware. An atta... |
| CVE-2021-46007 | CRITICAL | 9.8 | 3.6% | Mar 30, 2022 | totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command,... |
| CVE-2021-46006 | MEDIUM | 6.5 | 7.2% | Mar 30, 2022 | In Totolink A3100R V5.9c.4577, "test.asp" contains an API-like function, which is not authenticated. Using this function... |
| CVE-2021-43664 | HIGH | 8.1 | 1.7% | Mar 30, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component pr... |
| CVE-2021-33523 | HIGH | 7.2 | 1.8% | Mar 30, 2022 | MashZone NextGen through 10.7 GA allows a remote authenticated user, with access to the admin console, to upload a new J... |
| CVE-2021-45900 | MEDIUM | 6.5 | 0.7% | Mar 30, 2022 | Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configur... |
| CVE-2021-43142 | CRITICAL | 9.8 | 1.4% | Mar 30, 2022 | An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput. |
| CVE-2021-38362 | MEDIUM | 6.5 | 0.9% | Mar 30, 2022 | In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to a REST API endpoint tha... |
| CVE-2021-33581 | HIGH | 7.2 | 1.2% | Mar 30, 2022 | MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP servic... |
| CVE-2021-33208 | HIGH | 7.2 | 1.1% | Mar 30, 2022 | The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a ... |
| CVE-2021-40645 | MEDIUM | 6.5 | 1.1% | Mar 30, 2022 | An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataLi... |
| CVE-2021-40644 | MEDIUM | 6.5 | 1.1% | Mar 30, 2022 | An SQL Injection vulnerability exists in oasys oa_system as of 9/7/2021 in resources/mappers/notice-mapper.xml. |
| CVE-2021-45031 | HIGH | 7.7 | 0.8% | Mar 30, 2022 | A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate hi... |
| CVE-2021-44312 | HIGH | 8.8 | 0.4% | Mar 30, 2022 | An issue was discovered in Firmware Analysis and Comparison Tool v3.2. Logged in administrators could be targeted by a C... |
| CVE-2021-44310 | MEDIUM | 4.8 | 0.6% | Mar 30, 2022 | An issue was discovered in Firmware Analysis and Comparison Tool v3.2. With administrator privileges, the attacker could... |
| CVE-2021-3456 | HIGH | 7.1 | 0.2% | Mar 30, 2022 | An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients... |
| CVE-2021-39791 | MEDIUM | 5.5 | 0.1% | Mar 30, 2022 | In WallpaperManagerService, there is a possible way to determine whether an app is installed, without query permissions,... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now