2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41188MEDIUM5.4Shopware is open source e-commerce software. Versions prior to 5.7.6 contain a cross-site scripting vulnerability. This ...
CVE-2021-41185MEDIUM6.5Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with a...
CVE-2021-41184MEDIUM6.1jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option...
CVE-2021-41183MEDIUM6.1jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text`...
CVE-2021-41182MEDIUM6.1jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` ...
CVE-2021-41175MEDIUM5.4Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistic...
CVE-2021-41173MEDIUM5.7Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node i...
CVE-2021-41172MEDIUM5.4AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Sel...
CVE-2021-41158HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-41157MEDIUM5.3FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-37364HIGH7.8OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify perm...
CVE-2021-37363HIGH7.8An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.e...
CVE-2021-41078HIGH7.8Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.
CVE-2021-37372HIGH8.8Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can uplo...
CVE-2021-37371CRITICAL9.8Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login...
CVE-2021-26609HIGH7.5A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type paramete...
CVE-2021-26607CRITICAL9.8An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary com...
CVE-2021-41873CRITICAL10Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unau...
CVE-2021-42343CRITICAL9.8An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters starte...
CVE-2021-40345HIGH7.2An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can uplo...
CVE-2021-40344HIGH7.2An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can uplo...
CVE-2021-40343HIGH7.8An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios u...
CVE-2021-34596MEDIUM6.5A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCW...
CVE-2021-34595HIGH8.1A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 ...
CVE-2021-34593HIGH7.5In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid reque...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now