2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23261MEDIUM4.9Authenticated administrators may override the system configuration file and cause a denial of service.
CVE-2021-23260MEDIUM5.4Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and ...
CVE-2021-23259HIGH7.2Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib...
CVE-2021-23258HIGH7.2Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SP...
CVE-2021-43679CRITICAL9.8ecshop v2.7.3 is affected by a SQL injection vulnerability in shopex\ecshop\upload\api\client\api.php.
CVE-2021-43682MEDIUM6.1thinkphp-bjyblog (last update Jun 4 2021) is affected by a Cross Site Scripting (XSS) vulnerability in AdminBaseControll...
CVE-2021-43686MEDIUM6.1nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will ter...
CVE-2021-43683MEDIUM6.1pictshare v1.5 is affected by a Cross Site Scripting (XSS) vulnerability in api/info.php. The exit function will termina...
CVE-2021-43681MEDIUM6.1SakuraPanel v1.0.1.1 is affected by a Cross Site Scripting (XSS) vulnerability in /master/core/PostHandler.php. The exit...
CVE-2021-26777CRITICAL9.8Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concent...
CVE-2021-44227HIGH8.8In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that tok...
CVE-2021-43791MEDIUM5.3Zulip is an open source group chat application that combines real-time chat with threaded conversations. In affected ver...
CVE-2021-42711HIGH7.8Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This fil...
CVE-2021-33274CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33271CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33270CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33269CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33268CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33267CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33266CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-33265CRITICAL9.8D-Link DIR-809 devices with firmware through DIR-809Ax_FW1.12WWB03_20190410 were discovered to contain a stack buffer ov...
CVE-2021-43794MEDIUM5.3Discourse is an open source discussion platform. In affected versions an attacker can poison the cache for anonymous (i....
CVE-2021-43793MEDIUM4.3Discourse is an open source discussion platform. In affected versions a vulnerability in the Polls feature allowed users...
CVE-2021-43792MEDIUM4.3Discourse is an open source discussion platform. In affected versions a vulnerability affects users of tag groups who us...
CVE-2021-43137HIGH8.8Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now