2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21508 | MEDIUM | 6.7 | 0.1% | May 22, 2026 | Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin u... |
| CVE-2021-47981 | MEDIUM | 5.4 | 0.2% | May 16, 2026 | Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to i... |
| CVE-2021-47980 | HIGH | 7.1 | 0.2% | May 16, 2026 | Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database ... |
| CVE-2021-47979 | HIGH | 8.8 | 0.4% | May 16, 2026 | WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated at... |
| CVE-2021-47978 | MEDIUM | 6.9 | 0.8% | May 16, 2026 | ProcessMaker 3.5.4 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary... |
| CVE-2021-47977 | HIGH | 8.7 | 0.7% | May 16, 2026 | WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that... |
| CVE-2021-47976 | HIGH | 8.8 | 0.3% | May 16, 2026 | TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload a... |
| CVE-2021-47975 | HIGH | 7.2 | 0.2% | May 16, 2026 | WP Learn Manager 1.1.2 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inj... |
| CVE-2021-47974 | HIGH | 8.5 | 0.1% | May 16, 2026 | VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise serv... |
| CVE-2021-47973 | HIGH | 8.7 | 0.3% | May 16, 2026 | Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by p... |
| CVE-2021-47972 | HIGH | 8.7 | 0.3% | May 16, 2026 | Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the applica... |
| CVE-2021-47971 | HIGH | 8.7 | 0.3% | May 16, 2026 | My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting e... |
| CVE-2021-47970 | HIGH | 8.7 | 0.3% | May 16, 2026 | Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating ... |
| CVE-2021-47969 | HIGH | 8.7 | 0.3% | May 16, 2026 | Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting exc... |
| CVE-2021-47957 | MEDIUM | 6.4 | 0.2% | May 16, 2026 | Cookie Law Bar 1.2.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject ... |
| CVE-2021-47956 | HIGH | 8.8 | 0.3% | May 16, 2026 | EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da... |
| CVE-2021-47955 | MEDIUM | 5.4 | 0.2% | May 16, 2026 | CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary Ja... |
| CVE-2021-47954 | HIGH | 8.8 | 0.2% | May 16, 2026 | LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri... |
| CVE-2021-47952 | CRITICAL | 9.8 | 0.7% | May 16, 2026 | python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python... |
| CVE-2021-47942 | HIGH | 8.7 | 0.5% | May 16, 2026 | Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticate... |
| CVE-2021-47934 | MEDIUM | 6.9 | 0.2% | May 16, 2026 | MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts ... |
| CVE-2021-47968 | MEDIUM | 6.4 | 0.2% | May 15, 2026 | Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malic... |
| CVE-2021-47967 | MEDIUM | 6.1 | 0.2% | May 15, 2026 | PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject... |
| CVE-2021-47966 | HIGH | 8.8 | 0.3% | May 15, 2026 | PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid paramet... |
| CVE-2021-47965 | CRITICAL | 9.8 | 0.6% | May 15, 2026 | WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor com... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now