2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46322MEDIUM5.5Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack...
CVE-2021-46061CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via...
CVE-2021-29785MEDIUM5.9IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to pro...
CVE-2021-44245CRITICAL9.8An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) userna...
CVE-2021-44244CRITICAL9.8An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username para...
CVE-2021-44092CRITICAL9.8An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the adminis...
CVE-2021-44090CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
CVE-2021-45417HIGH7.8AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attribut...
CVE-2021-44091MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in reg...
CVE-2021-44829MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.
CVE-2021-44737HIGH8.8PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal ...
CVE-2021-44736CRITICAL9.8The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” fea...
CVE-2021-44735CRITICAL9.8Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
CVE-2021-44734CRITICAL9.8Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to ...
CVE-2021-44738CRITICAL9.8Buffer overflow vulnerability has been identified in Lexmark devices through 2021-12-07 in postscript interpreter.
CVE-2021-32039MEDIUM5.5Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS ...
CVE-2021-34600MEDIUM5.5Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used...
CVE-2021-45230MEDIUM6.5In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on D...
CVE-2021-3866MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6...
CVE-2021-43269HIGH8.8In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a maliciou...
CVE-2021-46028MEDIUM4.3In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF loa...
CVE-2021-46026MEDIUM5.4mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag...
CVE-2021-4143MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
CVE-2021-46027MEDIUM6.5mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSR...
CVE-2021-46025MEDIUM5.4A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now