2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-47964 | HIGH | 8.8 | 0.7% | May 15, 2026 | Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitra... |
| CVE-2021-47963 | HIGH | 7.2 | 0.5% | May 15, 2026 | Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by in... |
| CVE-2021-47962 | MEDIUM | 6.4 | 0.2% | May 15, 2026 | Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows ... |
| CVE-2021-47959 | HIGH | 8.7 | 0.5% | May 15, 2026 | WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exh... |
| CVE-2021-47958 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrar... |
| CVE-2021-26380 | LOW | 1.8 | 0.1% | May 15, 2026 | A compromised Trusted OS (TOS) driver could issue a malformed call that could potentially allow memory access outside t... |
| CVE-2021-47953 | MEDIUM | 5.3 | 0.1% | May 10, 2026 | OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by s... |
| CVE-2021-47951 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress Picture Gallery 1.4.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers... |
| CVE-2021-47950 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interfac... |
| CVE-2021-47949 | HIGH | 8.8 | 0.5% | May 10, 2026 | CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an... |
| CVE-2021-47948 | MEDIUM | 5.4 | 0.2% | May 10, 2026 | WordPress GetPaid Plugin 2.4.6 contains an HTML injection vulnerability that allows authenticated attackers to inject ar... |
| CVE-2021-47947 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mal... |
| CVE-2021-47946 | MEDIUM | 6.9 | 0.2% | May 10, 2026 | OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthent... |
| CVE-2021-47945 | HIGH | 8.5 | 0.1% | May 10, 2026 | Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local ... |
| CVE-2021-47944 | HIGH | 8.7 | 0.3% | May 10, 2026 | memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting ... |
| CVE-2021-47943 | HIGH | 8.8 | 0.6% | May 10, 2026 | TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbi... |
| CVE-2021-47941 | HIGH | 8.8 | 0.3% | May 10, 2026 | WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to ... |
| CVE-2021-47940 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allow... |
| CVE-2021-47939 | HIGH | 8.8 | 0.6% | May 10, 2026 | Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation ... |
| CVE-2021-47938 | HIGH | 8.8 | 0.6% | May 10, 2026 | ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows au... |
| CVE-2021-47937 | HIGH | 8.8 | 0.6% | May 10, 2026 | e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation pe... |
| CVE-2021-47936 | CRITICAL | 9.8 | 0.7% | May 10, 2026 | OpenCATS 0.9.4 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary... |
| CVE-2021-47935 | HIGH | 8.8 | 0.9% | May 10, 2026 | Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary co... |
| CVE-2021-47933 | CRITICAL | 9.8 | 0.6% | May 10, 2026 | WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to uplo... |
| CVE-2021-47932 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now