2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41039HIGH7.5In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property proper...
CVE-2021-43451CRITICAL9.8SQL Injection vulnerability exists in PHPGURUKUL Employee Record Management System 1.2 via the Email POST parameter in /...
CVE-2021-38575HIGH8.1NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
CVE-2021-42776HIGH7.7CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.
CVE-2021-29863MEDIUM4.3IBM QRadar SIEM 7.3 and 7.4 is vulnerable to server side request forgery (SSRF). This may allow an authenticated attacke...
CVE-2021-29849MEDIUM6.1IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2021-29779MEDIUM5.9IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exc...
CVE-2021-20400HIGH7.5IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h...
CVE-2021-44480HIGH8.1Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen...
CVE-2021-43687MEDIUM6.1chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an atta...
CVE-2021-43685CRITICAL9.8libretime hv3.0.0-alpha.10 is affected by a path manipulation vulnerability in /blob/master/legacy/application/modules/r...
CVE-2021-26334CRITICAL9.9The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may le...
CVE-2021-20611HIGH7.5Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/0...
CVE-2021-20610HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU...
CVE-2021-20609HIGH7.5Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Seri...
CVE-2021-44479MEDIUM5.5NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of ...
CVE-2021-43689MEDIUM6.1manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controll...
CVE-2021-40154MEDIUM5.5NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration req...
CVE-2021-44279MEDIUM6.1Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.
CVE-2021-44277MEDIUM6.1Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.
CVE-2021-25967MEDIUM5.4In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XSS vulnerability via SVG file upload of users’ profile pictur...
CVE-2021-44280CRITICAL9.8attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the make...
CVE-2021-43690MEDIUM6.1YurunProxy v0.01 is affected by a Cross Site Scripting (XSS) vulnerability in src/Client.php. The exit function will ter...
CVE-2021-3983MEDIUM6.1kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3964MEDIUM5.9elgg is vulnerable to Authorization Bypass Through User-Controlled Key

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now