2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41835HIGH7.5Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be...
CVE-2021-40247CRITICAL9.8SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to exe...
CVE-2021-33966MEDIUM5.4Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via ...
CVE-2021-33848MEDIUM6.1Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scrip...
CVE-2021-33846HIGH7.2Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticat...
CVE-2021-33843MEDIUM5.3Fresenius Kabi Agilia SP MC WiFi vD25 and prior has a default configuration page accessible without authentication. An a...
CVE-2021-31562CRITICAL9.1The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacke...
CVE-2021-23236HIGH7.5Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ versio...
CVE-2021-23233CRITICAL9.8Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information...
CVE-2021-23207MEDIUM5.5An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for t...
CVE-2021-23196CRITICAL9.8The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively ...
CVE-2021-23195MEDIUM5.3Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (dire...
CVE-2021-4016LOW3.3Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user ha...
CVE-2021-46309CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the userna...
CVE-2021-46308CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
CVE-2021-46307CRITICAL9.8An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.ph...
CVE-2021-46201CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /or...
CVE-2021-46200CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter ...
CVE-2021-46198CRITICAL9.8An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/aja...
CVE-2021-40855CRITICAL9.8The EU Technical Specifications for Digital COVID Certificates before 1.1 mishandle certificate governance. A non-produc...
CVE-2021-35004CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link TL-WA1201 1.0....
CVE-2021-35003CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer C90 1.0...
CVE-2021-46351MEDIUM5.5There is an Assertion 'local_tza == ecma_date_local_time_zone_adjustment (date_value)' failed at /jerry-core/ecma/builti...
CVE-2021-46350MEDIUM5.5There is an Assertion 'ecma_is_value_object (value)' failed at jerryscript/jerry-core/ecma/base/ecma-helpers-value.c in ...
CVE-2021-46349MEDIUM5.5There is an Assertion 'type == ECMA_OBJECT_TYPE_GENERAL || type == ECMA_OBJECT_TYPE_PROXY' failed at /jerry-core/ecma/op...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now