2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46385HIGH7.5https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information ...
CVE-2021-46114HIGH8.8jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides ...
CVE-2021-46561HIGH7.2controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb53830...
CVE-2021-29846LOW2.7IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient...
CVE-2021-29845HIGH8.8IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper inp...
CVE-2021-29838MEDIUM5.9IBM Security Guardium Insights 3.0 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2021-46386CRITICAL9.8File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafte...
CVE-2021-46383HIGH7.5https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information ...
CVE-2021-46118HIGH7.2jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The a...
CVE-2021-46116HIGH7.2jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin pan...
CVE-2021-46115HIGH7.2jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a f...
CVE-2021-46117HIGH7.2jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel...
CVE-2021-44692MEDIUM5.3BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new u...
CVE-2021-43334MEDIUM5.4BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.
CVE-2021-45975HIGH7.8In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs coul...
CVE-2021-22600HIGH7A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscal...
CVE-2021-22570MEDIUM5.5Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unche...
CVE-2021-44123HIGH8.8SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft...
CVE-2021-44122HIGH8.8SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/publi...
CVE-2021-44120MEDIUM5.4SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability in ecrire/public/interfaces.php, adding the functio...
CVE-2021-44118MEDIUM5.4SPIP 4.0.0 is affected by a Cross Site Scripting (XSS) vulnerability. To exploit the vulnerability, a visitor must brows...
CVE-2021-41766HIGH8.1Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX i...
CVE-2021-46560CRITICAL9.8The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
CVE-2021-46559HIGH7.5The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection me...
CVE-2021-36348HIGH8.1iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now