2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41660 | CRITICAL | 9.8 | 1.3% | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to ... |
| CVE-2021-41659 | CRITICAL | 9.8 | 1.3% | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL ... |
| CVE-2021-35005 | LOW | 3.3 | 0.9% | Jan 24, 2022 | This vulnerability allows local attackers to disclose sensitive information on affected installations of TeamViewer. An ... |
| CVE-2021-41658 | MEDIUM | 5.4 | 0.7% | Jan 24, 2022 | Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute ... |
| CVE-2021-4088 | HIGH | 7.2 | 2.3% | Jan 24, 2022 | SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.1... |
| CVE-2021-41472 | CRITICAL | 9.8 | 1.3% | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbi... |
| CVE-2021-41471 | CRITICAL | 9.8 | 1.2% | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers... |
| CVE-2021-40909 | CRITICAL | 9.6 | 2.2% | Jan 24, 2022 | Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tut... |
| CVE-2021-40908 | CRITICAL | 9.8 | 2.5% | Jan 24, 2022 | SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows atta... |
| CVE-2021-40907 | CRITICAL | 9.8 | 1.3% | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to... |
| CVE-2021-40596 | CRITICAL | 9.8 | 1.3% | Jan 24, 2022 | SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to e... |
| CVE-2021-44981 | HIGH | 8.8 | 3.7% | Jan 24, 2022 | In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it int... |
| CVE-2021-25083 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outp... |
| CVE-2021-25080 | MEDIUM | 6.1 | 84.8% | Jan 24, 2022 | The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved v... |
| CVE-2021-25079 | MEDIUM | 6.1 | 6.8% | Jan 24, 2022 | The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id,... |
| CVE-2021-25078 | MEDIUM | 6.1 | 2.3% | Jan 24, 2022 | The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests l... |
| CVE-2021-25076 | HIGH | 8.8 | 19.0% | Jan 24, 2022 | The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in... |
| CVE-2021-25074 | MEDIUM | 6.1 | 2.5% | Jan 24, 2022 | The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the sr... |
| CVE-2021-25073 | HIGH | 8.8 | 0.7% | Jan 24, 2022 | The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, al... |
| CVE-2021-25062 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outp... |
| CVE-2021-25049 | MEDIUM | 4.8 | 0.7% | Jan 24, 2022 | The Mobile Events Manager WordPress plugin before 1.4.4 does not sanitise and escape various of its settings, allowing h... |
| CVE-2021-25045 | HIGH | 7.2 | 1.5% | Jan 24, 2022 | The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in ... |
| CVE-2021-25035 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error paramete... |
| CVE-2021-25031 | MEDIUM | 6.1 | 0.9% | Jan 24, 2022 | The Image Hover Effects Ultimate (Image Gallery, Effects, Lightbox, Comparison or Magnifier) WordPress plugin before 9.7... |
| CVE-2021-25028 | MEDIUM | 6.1 | 1.9% | Jan 24, 2022 | The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirec... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now