2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25991HIGH7.3In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins ...
CVE-2021-25990MEDIUM5.4In “ifme”, versions v7.22.0 to v7.31.4 are vulnerable against self-stored XSS in the contacts field as it allows loading...
CVE-2021-25989MEDIUM5.4In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability in the markdown editor. It can be e...
CVE-2021-25988MEDIUM5.4In “ifme”, versions 1.0.0 to v7.31.4 are vulnerable against stored XSS vulnerability (notifications section) which can b...
CVE-2021-44161HIGH8.8Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input...
CVE-2021-44160HIGH7.3Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire anoth...
CVE-2021-44832MEDIUM6.6Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a r...
CVE-2021-44771Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-43556HIGH7.8FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing projec...
CVE-2021-43554HIGH7.8FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files...
CVE-2021-42583HIGH7.5A Broken or Risky Cryptographic Algorithm exists in Max Mazurov Maddy before 0.5.2, which is an unnecessary risk that ma...
CVE-2021-3095Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43551. Reason: This candidate is a reservation d...
CVE-2021-3090Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43553. Reason: This candidate is a reservation d...
CVE-2021-23151Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-45814CRITICAL9.8Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel ...
CVE-2021-45813MEDIUM6.1SLICAN WebCTI 1.01 2015 is affected by a Cross Site Scripting (XSS) vulnerability. The attacker can steal the user's ses...
CVE-2021-45812MEDIUM6.1NUUO Network Video Recorder NVRsolo 3.9.1 is affected by a Cross Site Scripting (XSS) vulnerability. An attacker can ste...
CVE-2021-45903MEDIUM6.1A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x bef...
CVE-2021-45425MEDIUM6.1Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScrip...
CVE-2021-37401CRITICAL9.8An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a...
CVE-2021-37400CRITICAL9.8An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PL...
CVE-2021-40579MEDIUM6.5https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected b...
CVE-2021-35032HIGH7.8A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local u...
CVE-2021-35031HIGH8A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware...
CVE-2021-4179MEDIUM5.4livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now