2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-47931MEDIUM6.4Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject mali...
CVE-2021-47930HIGH8.8Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handle...
CVE-2021-47929MEDIUM6.4Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attacker...
CVE-2021-47928HIGH8.8Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to ext...
CVE-2021-47927MEDIUM6.4WordPress Plugin WP Symposium Pro 2021.10 contains a stored cross-site scripting vulnerability that allows authenticated...
CVE-2021-47926MEDIUM6.4Contact Form to Email 1.3.24 contains a stored cross-site scripting vulnerability that allows authenticated attackers to...
CVE-2021-47925MEDIUM6.4CMDBuild 3.3.2 contains multiple stored cross-site scripting vulnerabilities that allow authenticated attackers to injec...
CVE-2021-47924MEDIUM6.4Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attacker...
CVE-2021-47923CRITICAL9.8OpenCart 3.0.3.8 contains a session fixation vulnerability that allows attackers to hijack user sessions by injecting ar...
CVE-2021-47922MEDIUM6.4Slider by Soliloquy 2.6.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to in...
CVE-2021-47910MEDIUM6.4AccessPress Social Icons 1.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers ...
CVE-2021-47907MEDIUM6.4Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authent...
CVE-2021-36438MEDIUM6.5SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobpor...
CVE-2021-47961HIGH8.1A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to ...
CVE-2021-47960MEDIUM6.5A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows ...
CVE-2021-4473CRITICAL9.8Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoin...
CVE-2021-4477CRITICAL9.3Hirschmann HiLCOS OpenBAT and BAT450 products contain a firewall bypass vulnerability in IPv6 IPsec deployments that all...
CVE-2021-4474MEDIUM6.9Ruckus Access Point products contain an arbitrary file read vulnerability in the command-line interface that allows auth...
CVE-2021-35486HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote a...
CVE-2021-35485HIGH8The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to ...
CVE-2021-35484HIGH8.2Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL...
CVE-2021-35483MEDIUM4.1The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to ...
CVE-2021-4456MEDIUM6.5Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact....
CVE-2021-35402CRITICAL10PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metac...
CVE-2021-26410LOW1.8Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter valu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now