2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-46072 | MEDIUM | 4.8 | 2.7% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S... |
| CVE-2021-46071 | MEDIUM | 4.8 | 2.7% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List ... |
| CVE-2021-46070 | MEDIUM | 4.8 | 0.9% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Reques... |
| CVE-2021-46069 | MEDIUM | 4.8 | 2.7% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List ... |
| CVE-2021-46068 | MEDIUM | 4.8 | 2.7% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec... |
| CVE-2021-46067 | CRITICAL | 9.8 | 5.1% | Jan 6, 2022 | In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover. |
| CVE-2021-45745 | MEDIUM | 5.4 | 1.4% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel. |
| CVE-2021-45744 | MEDIUM | 5.4 | 1.4% | Jan 6, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. |
| CVE-2021-46080 | MEDIUM | 4.8 | 0.6% | Jan 6, 2022 | A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF at... |
| CVE-2021-46076 | HIGH | 8.8 | 3.3% | Jan 6, 2022 | Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious ph... |
| CVE-2021-44591 | MEDIUM | 6.5 | 1.0% | Jan 6, 2022 | In libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denia... |
| CVE-2021-44590 | MEDIUM | 6.5 | 1.2% | Jan 6, 2022 | In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could... |
| CVE-2021-45458 | HIGH | 7.5 | 2.1% | Jan 6, 2022 | Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the enc... |
| CVE-2021-45457 | HIGH | 7.5 | 2.3% | Jan 6, 2022 | In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apach... |
| CVE-2021-45456 | CRITICAL | 9.8 | 88.6% | Jan 6, 2022 | Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the ... |
| CVE-2021-44878 | HIGH | 7.5 | 0.9% | Jan 6, 2022 | If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) d... |
| CVE-2021-44584 | MEDIUM | 6.1 | 0.9% | Jan 6, 2022 | Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject ar... |
| CVE-2021-36774 | MEDIUM | 6.5 | 1.9% | Jan 6, 2022 | Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain pr... |
| CVE-2021-31522 | CRITICAL | 9.8 | 2.9% | Jan 6, 2022 | Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2.... |
| CVE-2021-27738 | HIGH | 7.5 | 2.6% | Jan 6, 2022 | All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API end... |
| CVE-2021-44564 | HIGH | 8.1 | 0.9% | Jan 6, 2022 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC de... |
| CVE-2021-44351 | HIGH | 7.5 | 1.8% | Jan 6, 2022 | An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter. |
| CVE-2021-36739 | MEDIUM | 6.1 | 2.3% | Jan 6, 2022 | The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to ... |
| CVE-2021-36738 | MEDIUM | 6.1 | 2.3% | Jan 6, 2022 | The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scrip... |
| CVE-2021-36737 | MEDIUM | 6.1 | 2.3% | Jan 6, 2022 | The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should m... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now