2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45966CRITICAL9.8An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.p...
CVE-2021-44088CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacke...
CVE-2021-44087CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an ...
CVE-2021-43961MEDIUM4.3Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
CVE-2021-46107HIGH7.5Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacke...
CVE-2021-45040CRITICAL9.8The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload...
CVE-2021-44907Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-44906CRITICAL9.8Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CVE-2021-44262HIGH7.5A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote att...
CVE-2021-44261MEDIUM5.3A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote at...
CVE-2021-44260HIGH7.5A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al...
CVE-2021-44259CRITICAL9.8A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a ...
CVE-2021-45794HIGH7.5Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.
CVE-2021-45793HIGH7.5Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
CVE-2021-44908CRITICAL9.8SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadAction...
CVE-2021-23771MEDIUM6.5This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox E...
CVE-2021-23632CRITICAL9.8All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git met...
CVE-2021-23556HIGH8The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_com...
CVE-2021-45792MEDIUM4.8Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.
CVE-2021-45791HIGH8.8Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/mem...
CVE-2021-42219HIGH7.5Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sen...
CVE-2021-45822MEDIUM6.1A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/send...
CVE-2021-23648MEDIUM6.1The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitizati...
CVE-2021-45821HIGH8.8A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file th...
CVE-2021-42730HIGH7.8Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now