2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-47830 | MEDIUM | 6.5 | 0.3% | Jan 21, 2026 | GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can cra... |
| CVE-2021-47817 | MEDIUM | 5.4 | 0.7% | Jan 21, 2026 | OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers ca... |
| CVE-2021-47844 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind ma... |
| CVE-2021-47841 | MEDIUM | 6.1 | 0.4% | Jan 16, 2026 | SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into ... |
| CVE-2021-47836 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thr... |
| CVE-2021-47834 | MEDIUM | 6.4 | 0.2% | Jan 16, 2026 | Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject ma... |
| CVE-2021-47820 | MEDIUM | 5.3 | 0.2% | Jan 16, 2026 | Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without us... |
| CVE-2021-47814 | MEDIUM | 5.5 | 0.4% | Jan 16, 2026 | NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing... |
| CVE-2021-47808 | MEDIUM | 5.4 | 0.2% | Jan 16, 2026 | Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title ... |
| CVE-2021-47800 | MEDIUM | 6.9 | 0.2% | Jan 16, 2026 | b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account deta... |
| CVE-2021-47783 | MEDIUM | 5.4 | 0.3% | Jan 16, 2026 | Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files wi... |
| CVE-2021-47843 | MEDIUM | 5.4 | 0.4% | Jan 15, 2026 | Tagstoo 2.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious payloads th... |
| CVE-2021-47776 | MEDIUM | 6.9 | 0.3% | Jan 15, 2026 | Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl par... |
| CVE-2021-47771 | MEDIUM | 6.8 | 0.2% | Jan 15, 2026 | RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to... |
| CVE-2021-47769 | MEDIUM | 5.1 | 0.3% | Jan 15, 2026 | Isshue Shopping Cart 3.5 contains a persistent cross-site scripting vulnerability in title input fields across stock, cu... |
| CVE-2021-47768 | MEDIUM | 6.1 | 0.3% | Jan 15, 2026 | ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows re... |
| CVE-2021-47765 | MEDIUM | 6.7 | 0.2% | Jan 15, 2026 | AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by ... |
| CVE-2021-47764 | MEDIUM | 6.7 | 0.2% | Jan 15, 2026 | AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by ... |
| CVE-2021-47759 | MEDIUM | 6.8 | 0.1% | Jan 15, 2026 | MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH conne... |
| CVE-2021-47754 | MEDIUM | 6.9 | 0.2% | Jan 15, 2026 | Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settin... |
| CVE-2021-47750 | MEDIUM | 6.1 | 0.3% | Jan 13, 2026 | YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts throug... |
| CVE-2021-41074 | MEDIUM | 5.4 | 0.1% | Jan 12, 2026 | A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a ... |
| CVE-2021-47743 | MEDIUM | 6.1 | 0.2% | Dec 31, 2025 | COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in... |
| CVE-2021-47725 | MEDIUM | 5.4 | 0.2% | Dec 31, 2025 | STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authentica... |
| CVE-2021-47738 | MEDIUM | 5.4 | 0.2% | Dec 23, 2025 | CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now