2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43141MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter i...
CVE-2021-43140CRITICAL9.8SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
CVE-2021-41174MEDIUM6.1Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to conv...
CVE-2021-41134MEDIUM5.4nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (...
CVE-2021-23820CRITICAL9.8This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 ...
CVE-2021-23807CRITICAL9.8This affects the package jsonpointer before 5.0.0. A type confusion vulnerability can lead to a bypass of a previous Pro...
CVE-2021-23784MEDIUM6.1This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is r...
CVE-2021-23624CRITICAL9.8This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when ...
CVE-2021-23509CRITICAL9.8This affects the package json-ptr before 3.0.0. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 whe...
CVE-2021-23472MEDIUM6.1This affects versions before 1.19.1 of package bootstrap-table. A type confusion vulnerability can lead to a bypass of i...
CVE-2021-40985MEDIUM5.5A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BM...
CVE-2021-27836MEDIUM6.5An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial o...
CVE-2021-26786HIGH8.8An issue was discoverered in in customercentric-selling-poland PlayTube, allows authenticated attackers to execute arbit...
CVE-2021-43082CRITICAL9.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in the stats-over-http plugin of Ap...
CVE-2021-41585HIGH7.5Improper Input Validation vulnerability in accepting socket connections in Apache Traffic Server allows an attacker to m...
CVE-2021-38161HIGH8.1Improper Authentication vulnerability in TLS origin verification of Apache Traffic Server allows for man in the middle a...
CVE-2021-37149HIGH7.5Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request...
CVE-2021-37148HIGH7.5Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request...
CVE-2021-37147HIGH7.5Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle request...
CVE-2021-43324MEDIUM6.1LibreNMS through 21.10.2 allows XSS via a widget title.
CVE-2021-43130CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the userna...
CVE-2021-36698MEDIUM5.4Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
CVE-2021-36697MEDIUM6.7With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component...
CVE-2021-40849CRITICAL9.8In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable ...
CVE-2021-40848HIGH7.8In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now