2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42642HIGH7.5PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul...
CVE-2021-42641HIGH7.5PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul...
CVE-2021-42640CRITICAL9.1PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vul...
CVE-2021-42639MEDIUM6.1PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulner...
CVE-2021-42637CRITICAL9.8PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server ...
CVE-2021-42633MEDIUM5.3PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to SQL Injection, which may allow an attacker to ...
CVE-2021-41018HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2021-39070CRITICAL9.8IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabl...
CVE-2021-39066HIGH8.8IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker th...
CVE-2021-39044HIGH8.8IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2021-36193HIGH7.2Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticate...
CVE-2021-24043CRITICAL9.1A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android ...
CVE-2021-43073HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2021-43062MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0...
CVE-2021-42753HIGH8.1An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb man...
CVE-2021-41016HIGH8.8A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version ...
CVE-2021-36177MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and below, 6.2.x, 6.1.x, 6.0.x...
CVE-2021-42638HIGH8.1PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code exe...
CVE-2021-46093CRITICAL9.8eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
CVE-2021-38560MEDIUM6.1Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in ...
CVE-2021-44746MEDIUM5.3UNIVERGE DT 820 V3.2.7.0 and prior, UNIVERGE DT 830 V5.2.7.0 and prior, UNIVERGE DT 930 V2.4.0.0 and prior, IP Phone Man...
CVE-2021-44451MEDIUM6.5Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated us...
CVE-2021-43510CRITICAL9.8SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login...
CVE-2021-43509CRITICAL9.8SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-se...
CVE-2021-46253MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Create Post function of Anchor CMS v0.12.7 allows attackers to execute...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now