2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41674CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/logi...
CVE-2021-3756CRITICAL9.8libmysofa is vulnerable to Heap-based Buffer Overflow
CVE-2021-41186HIGH7.5Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The par...
CVE-2021-39179HIGH8.8DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection v...
CVE-2021-35237MEDIUM4.3A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacki...
CVE-2021-3662MEDIUM5.4Certain HP Enterprise LaserJet and PageWide MFPs may be vulnerable to stored cross site scripting (XSS).
CVE-2021-3441MEDIUM4.8A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross...
CVE-2021-22038HIGH8.8On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally c...
CVE-2021-22037HIGH7.8Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The...
CVE-2021-31862MEDIUM6.1SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
CVE-2021-31627HIGH8.8Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows atta...
CVE-2021-31624HIGH8.8Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows atta...
CVE-2021-25742HIGH7.1A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the cust...
CVE-2021-41194CRITICAL9.8FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to Jupy...
CVE-2021-36551MEDIUM5.4TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-calendar.php. ...
CVE-2021-36550MEDIUM5.4TikiWiki v21.4 was discovered to contain a cross-site scripting (XSS) vulnerability in the component tiki-browse_categor...
CVE-2021-36548CRITICAL9.8A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=bl...
CVE-2021-36547CRITICAL9.8A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attacker...
CVE-2021-30840HIGH7.8This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processi...
CVE-2021-30836MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvO...
CVE-2021-30834HIGH7.8A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iO...
CVE-2021-30833MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.0.1. Unpacking a maliciously cra...
CVE-2021-30831MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 an...
CVE-2021-30824HIGH7.8A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, Se...
CVE-2021-30823MEDIUM6.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.0.1, iOS 14.8 and iPadO...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now