2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-47931 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mali... |
| CVE-2021-47930 | HIGH | 8.8 | 0.3% | May 10, 2026 | Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handle... |
| CVE-2021-47929 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attacker... |
| CVE-2021-47928 | HIGH | 8.8 | 0.3% | May 10, 2026 | Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to ext... |
| CVE-2021-47927 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated... |
| CVE-2021-47926 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to... |
| CVE-2021-47925 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to injec... |
| CVE-2021-47924 | MEDIUM | 6.4 | 0.3% | May 10, 2026 | Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attacker... |
| CVE-2021-47923 | CRITICAL | 9.8 | 0.4% | May 10, 2026 | OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting ar... |
| CVE-2021-47922 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in... |
| CVE-2021-47910 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers ... |
| CVE-2021-47907 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authent... |
| CVE-2021-36438 | MEDIUM | 6.5 | 0.2% | Apr 27, 2026 | SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobpor... |
| CVE-2021-47961 | HIGH | 8.1 | 0.3% | Apr 10, 2026 | A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to ... |
| CVE-2021-47960 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows ... |
| CVE-2021-4473 | CRITICAL | 9.8 | 6.2% | Apr 7, 2026 | Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoin... |
| CVE-2021-4477 | CRITICAL | 9.3 | 0.3% | Apr 3, 2026 | Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that all... |
| CVE-2021-4474 | MEDIUM | 6.9 | 0.5% | Mar 26, 2026 | Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows auth... |
| CVE-2021-35486 | HIGH | 8.1 | 0.2% | Mar 3, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote a... |
| CVE-2021-35485 | HIGH | 8 | 0.2% | Mar 3, 2026 | The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to ... |
| CVE-2021-35484 | HIGH | 8.2 | 0.2% | Mar 3, 2026 | Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL... |
| CVE-2021-35483 | MEDIUM | 4.1 | 0.2% | Mar 3, 2026 | The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to ... |
| CVE-2021-4456 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact.... |
| CVE-2021-35402 | CRITICAL | 10 | 1.0% | Feb 20, 2026 | PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metac... |
| CVE-2021-26410 | LOW | 1.8 | 0.1% | Feb 10, 2026 | Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter valu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now