2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39739LOW3.3In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead ...
CVE-2021-23851HIGH7.2A specially crafted TCP/IP packet may cause the camera recovery image web interface to crash. It may also cause a buffer...
CVE-2021-23850HIGH7.2A specially crafted TCP/IP packet may cause a camera recovery image telnet interface to crash. It may also cause a buffe...
CVE-2021-1033HIGH7.8In createGeneralSlice of ConnectedDevicesSliceProvider.java.java, there is a possible permission bypass due to an unsafe...
CVE-2021-1000HIGH7.8In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an uns...
CVE-2021-41594MEDIUM6.5In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by inte...
CVE-2021-44082HIGH8.3textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthentica...
CVE-2021-43118CRITICAL9.8A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek V...
CVE-2021-42911CRITICAL9.8A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor ...
CVE-2021-43110CRITICAL9.8An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.
CVE-2021-43109HIGH7.5An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in pr...
CVE-2021-42970MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter.
CVE-2021-44081HIGH7.5A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 character...
CVE-2021-43701MEDIUM6.5CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/articl...
CVE-2021-22572MEDIUM5.5On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File....
CVE-2021-46743CRITICAL9.1In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) hea...
CVE-2021-45866MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via ...
CVE-2021-45865CRITICAL9.8A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functio...
CVE-2021-44581HIGH7.5An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
CVE-2021-43105MEDIUM4.3A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific maliciou...
CVE-2021-43103HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote m...
CVE-2021-43102HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote ma...
CVE-2021-43101HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a...
CVE-2021-43100HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote m...
CVE-2021-43099MEDIUM4.9An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now