2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43439CRITICAL9.8RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely
CVE-2021-43438MEDIUM5.4Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field
CVE-2021-43437HIGH8.8In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the we...
CVE-2021-44525CRITICAL9.8Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a fi...
CVE-2021-44676CRITICAL9.8Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control detail...
CVE-2021-44675CRITICAL9.8Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution du...
CVE-2021-44916MEDIUM6.1Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad...
CVE-2021-44790CRITICAL9.8A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from ...
CVE-2021-44224HIGH8.2A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference...
CVE-2021-41561HIGH7.5Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet f...
CVE-2021-44858HIGH7.5An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us...
CVE-2021-44554MEDIUM5.3Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /...
CVE-2021-44263MEDIUM5.4Gurock TestRail before 7.2.4 mishandles HTML escaping.
CVE-2021-42913HIGH7.5The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and clea...
CVE-2021-44732CRITICAL9.8Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_sessi...
CVE-2021-44164CRITICAL9.8Chain Sea ai chatbot system’s file upload function has insufficient filtering for special characters in URLs, which allo...
CVE-2021-44163MEDIUM6.1Chain Sea ai chatbot backend has improper filtering of special characters in URL parameters, which allows a remote attac...
CVE-2021-44162HIGH7.5Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has imprope...
CVE-2021-44159CRITICAL9.84MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary fil...
CVE-2021-4136HIGH7.8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-45041HIGH8.8SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project mo...
CVE-2021-43083HIGH8.8Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow f...
CVE-2021-45105MEDIUM5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursio...
CVE-2021-4131HIGH8.8livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4130HIGH8.8snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now