2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45966 | CRITICAL | 9.8 | 5.6% | Mar 18, 2022 | An issue was discovered in Pascom Cloud Phone System before 7.20.x. In the management REST API, /services/apply in exd.p... |
| CVE-2021-44088 | CRITICAL | 9.8 | 3.3% | Mar 17, 2022 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacke... |
| CVE-2021-44087 | CRITICAL | 9.8 | 4.7% | Mar 17, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an ... |
| CVE-2021-43961 | MEDIUM | 4.3 | 0.7% | Mar 17, 2022 | Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection. |
| CVE-2021-46107 | HIGH | 7.5 | 7.4% | Mar 17, 2022 | Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacke... |
| CVE-2021-45040 | CRITICAL | 9.8 | 3.1% | Mar 17, 2022 | The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows remote attackers to upload... |
| CVE-2021-44907 | — | — | — | Mar 17, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-44906 | CRITICAL | 9.8 | 4.6% | Mar 17, 2022 | Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). |
| CVE-2021-44262 | HIGH | 7.5 | 2.2% | Mar 17, 2022 | A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote att... |
| CVE-2021-44261 | MEDIUM | 5.3 | 20.8% | Mar 17, 2022 | A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13, which can allow a remote at... |
| CVE-2021-44260 | HIGH | 7.5 | 7.6% | Mar 17, 2022 | A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can al... |
| CVE-2021-44259 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a ... |
| CVE-2021-45794 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. |
| CVE-2021-45793 | HIGH | 7.5 | 4.6% | Mar 17, 2022 | Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. |
| CVE-2021-44908 | CRITICAL | 9.8 | 1.8% | Mar 17, 2022 | SailsJS Sails.js <=1.4.0 is vulnerable to Prototype Pollution via controller/load-action-modules.js, function loadAction... |
| CVE-2021-23771 | MEDIUM | 6.5 | 1.0% | Mar 17, 2022 | This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox E... |
| CVE-2021-23632 | CRITICAL | 9.8 | 2.2% | Mar 17, 2022 | All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git met... |
| CVE-2021-23556 | HIGH | 8 | 1.1% | Mar 17, 2022 | The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_com... |
| CVE-2021-45792 | MEDIUM | 4.8 | 0.5% | Mar 17, 2022 | Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php. |
| CVE-2021-45791 | HIGH | 8.8 | 1.0% | Mar 17, 2022 | Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/mem... |
| CVE-2021-42219 | HIGH | 7.5 | 1.2% | Mar 17, 2022 | Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sen... |
| CVE-2021-45822 | MEDIUM | 6.1 | 1.0% | Mar 16, 2022 | A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/send... |
| CVE-2021-23648 | MEDIUM | 6.1 | 1.4% | Mar 16, 2022 | The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitizati... |
| CVE-2021-45821 | HIGH | 8.8 | 2.5% | Mar 16, 2022 | A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.php file th... |
| CVE-2021-42730 | HIGH | 7.8 | 1.7% | Mar 16, 2022 | Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now