2021 CVE Vulnerabilities

23,431 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-47957MEDIUM5.1Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject ...
CVE-2021-47956HIGH8.8EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da...
CVE-2021-47955MEDIUM5.1CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary Ja...
CVE-2021-47954HIGH8.8LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri...
CVE-2021-47952CRITICAL9.3python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python...
CVE-2021-47942HIGH8.7Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticate...
CVE-2021-47934MEDIUM6.9MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts ...
CVE-2021-47968MEDIUM5.1Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malic...
CVE-2021-47967MEDIUM5.1PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject...
CVE-2021-47966HIGH8.8PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid paramet...
CVE-2021-47965CRITICAL9.3WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor com...
CVE-2021-47964HIGH8.7Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitra...
CVE-2021-47963MEDIUM5.1Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by in...
CVE-2021-47962MEDIUM5.1Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows ...
CVE-2021-47959HIGH8.7WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exh...
CVE-2021-47958MEDIUM5.3CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrar...
CVE-2021-26380LOW1.8A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside t...
CVE-2021-47953MEDIUM5.3OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by s...
CVE-2021-47951MEDIUM5.1WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers...
CVE-2021-47950MEDIUM5.1Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interfac...
CVE-2021-47949HIGH8.7CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an...
CVE-2021-47948MEDIUM5.1WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject ar...
CVE-2021-47947MEDIUM5.1Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal...
CVE-2021-47946MEDIUM6.9OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthent...
CVE-2021-47945HIGH8.5Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now