2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21873CRITICAL9.1A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can mak...
CVE-2021-21872CRITICAL9.9An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix Premi...
CVE-2021-45267MEDIUM5.5An invalid memory address dereference vulnerability exists in gpac 1.1.0 via the svg_node_start function, which causes a...
CVE-2021-45266HIGH7.5A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a s...
CVE-2021-45263MEDIUM5.5An invalid free vulnerability exists in gpac 1.1.0 via the gf_svg_delete_attribute_value function, which causes a segmen...
CVE-2021-45262MEDIUM5.5An invalid free vulnerability exists in gpac 1.1.0 via the gf_sg_command_del function, which causes a segmentation fault...
CVE-2021-45261MEDIUM5.5An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service...
CVE-2021-45260MEDIUM5.5A null pointer dereference vulnerability exists in gpac 1.1.0 in the lsr_read_id.part function, which causes a segmentat...
CVE-2021-44659CRITICAL9.8Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action...
CVE-2021-43804HIGH7.3PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2021-43631CRITICAL9.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment...
CVE-2021-43630HIGH8.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php....
CVE-2021-43629CRITICAL9.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
CVE-2021-43628CRITICAL9.8Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
CVE-2021-43158MEDIUM4.3In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to rem...
CVE-2021-43157CRITICAL9.8Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
CVE-2021-43156MEDIUM6.5In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete a...
CVE-2021-43155CRITICAL9.8Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.
CVE-2021-37706CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2021-4114Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2021-4113Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2021-45419HIGH8.8Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <...
CVE-2021-45259MEDIUM5.5An Invalid pointer reference vulnerability exists in gpac 1.1.0 via the gf_svg_node_del function, which causes a segment...
CVE-2021-45258MEDIUM5.5A stack overflow vulnerability exists in gpac 1.1.0 via the gf_bifs_dec_proto_list function, which causes a segmentation...
CVE-2021-45257MEDIUM5.5An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now