2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-47924 | MEDIUM | 6.4 | 0.3% | May 10, 2026 | Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attacker... |
| CVE-2021-47922 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in... |
| CVE-2021-47910 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers ... |
| CVE-2021-47907 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authent... |
| CVE-2021-36438 | MEDIUM | 6.5 | 0.2% | Apr 27, 2026 | SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobpor... |
| CVE-2021-47960 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows ... |
| CVE-2021-4474 | MEDIUM | 6.9 | 0.5% | Mar 26, 2026 | Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows auth... |
| CVE-2021-35483 | MEDIUM | 4.1 | 0.2% | Mar 3, 2026 | The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to ... |
| CVE-2021-4456 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact.... |
| CVE-2021-47920 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers t... |
| CVE-2021-47919 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Atta... |
| CVE-2021-47917 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote atta... |
| CVE-2021-47914 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted paramete... |
| CVE-2021-47913 | MEDIUM | 5.4 | 0.2% | Feb 1, 2026 | PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users... |
| CVE-2021-47912 | MEDIUM | 5.4 | 0.2% | Feb 1, 2026 | PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and ... |
| CVE-2021-47911 | MEDIUM | 5.4 | 0.2% | Feb 1, 2026 | Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. A... |
| CVE-2021-47908 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remo... |
| CVE-2021-47885 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment in... |
| CVE-2021-47856 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword... |
| CVE-2021-47906 | MEDIUM | 6.4 | 0.2% | Jan 23, 2026 | BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authe... |
| CVE-2021-47905 | MEDIUM | 6.1 | 0.2% | Jan 23, 2026 | MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field.... |
| CVE-2021-47899 | MEDIUM | 6.9 | 0.3% | Jan 23, 2026 | YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read l... |
| CVE-2021-47870 | MEDIUM | 5.4 | 0.2% | Jan 21, 2026 | GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin at... |
| CVE-2021-47860 | MEDIUM | 4.3 | 0.2% | Jan 21, 2026 | GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attac... |
| CVE-2021-47857 | MEDIUM | 6.1 | 0.3% | Jan 21, 2026 | Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now