2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46072MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service List S...
CVE-2021-46071MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List ...
CVE-2021-46070MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Service Reques...
CVE-2021-46069MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Mechanic List ...
CVE-2021-46068MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the My Account Sec...
CVE-2021-46067CRITICAL9.8In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.
CVE-2021-45745MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.
CVE-2021-45744MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.
CVE-2021-46080MEDIUM4.8A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF at...
CVE-2021-46076HIGH8.8Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious ph...
CVE-2021-44591MEDIUM6.5In libming 0.4.8, the parseSWF_DEFINELOSSLESS2 function in util/parser.c lacks a boundary check that would lead to denia...
CVE-2021-44590MEDIUM6.5In libming 0.4.8, a memory exhaustion vulnerability exist in the function cws2fws in util/main.c. Remote attackers could...
CVE-2021-45458HIGH7.5Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the enc...
CVE-2021-45457HIGH7.5In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apach...
CVE-2021-45456CRITICAL9.8Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the ...
CVE-2021-44878HIGH7.5If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) d...
CVE-2021-44584MEDIUM6.1Cross-site scripting (XSS) vulnerability in index.php in emlog version <= pro-1.0.7 allows remote attackers to inject ar...
CVE-2021-36774MEDIUM6.5Apache Kylin allows users to read data from other database systems using JDBC. The MySQL JDBC driver supports certain pr...
CVE-2021-31522CRITICAL9.8Kylin can receive user input and load any class through Class.forName(...). This issue affects Apache Kylin 2 version 2....
CVE-2021-27738HIGH7.5All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API end...
CVE-2021-44564HIGH8.1A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC de...
CVE-2021-44351HIGH7.5An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.
CVE-2021-36739MEDIUM6.1The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to ...
CVE-2021-36738MEDIUM6.1The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scrip...
CVE-2021-36737MEDIUM6.1The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should m...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now