2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31632CRITICAL9.8b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the Use...
CVE-2021-31631HIGH8.8b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulne...
CVE-2021-4075HIGH7.2snipe-it is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2021-40313HIGH8.8Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager...
CVE-2021-40091CRITICAL9.8An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.
CVE-2021-37298Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-36567CRITICAL9.8ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Stor...
CVE-2021-36564CRITICAL9.8ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cach...
CVE-2021-43800HIGH7.5Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is poss...
CVE-2021-43936CRITICAL9.8The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automa...
CVE-2021-43931CRITICAL9.8The authentication algorithm of the WebHMI portal is sound, but the implemented mechanism can be bypassed as the result ...
CVE-2021-43784MEDIUM5runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is ...
CVE-2021-43781MEDIUM4.3Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. ...
CVE-2021-39890CRITICAL9.8It was possible to bypass 2FA for LDAP users and access some specific pages with Basic Authentication in GitLab 14.1.1 a...
CVE-2021-22170HIGH7.5Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encr...
CVE-2021-36198HIGH7.5Successful exploitation of this vulnerability could allow an unauthorized user to access sensitive data.
CVE-2021-35245MEDIUM6.8When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed o...
CVE-2021-35242HIGH8.8Serv-U server responds with valid CSRFToken when the request contains only Session.
CVE-2021-25041MEDIUM6.1The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues v...
CVE-2021-24943CRITICAL9.8The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the...
CVE-2021-24939MEDIUM6.1The LoginWP (Formerly Peter's Login Redirect) WordPress plugin before 3.0.0.5 does not sanitise and escape the rul_login...
CVE-2021-24938MEDIUM6.1The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_da...
CVE-2021-24935MEDIUM6.1The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family pa...
CVE-2021-24931CRITICAL9.8The Secure Copy Content Protection and Content Locking WordPress plugin before 2.8.2 does not escape the sccp_id paramet...
CVE-2021-24930MEDIUM5.4The WordPress Online Booking and Scheduling Plugin WordPress plugin before 20.3.1 does not escape the Staff Full Name fi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now