2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37823 | MEDIUM | 4.9 | 0.7% | Nov 3, 2022 | OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the backgroun... |
| CVE-2021-46853 | MEDIUM | 5.9 | 0.8% | Nov 3, 2022 | Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent be... |
| CVE-2021-45448 | MEDIUM | 6.5 | 0.6% | Nov 2, 2022 | Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a ser... |
| CVE-2021-36864 | MEDIUM | 5.4 | 0.4% | Oct 28, 2022 | Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4... |
| CVE-2021-38728 | MEDIUM | 6.1 | 0.4% | Oct 28, 2022 | SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php. |
| CVE-2021-36863 | MEDIUM | 5.4 | 0.4% | Oct 28, 2022 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3... |
| CVE-2021-36858 | MEDIUM | 4.8 | 0.4% | Oct 28, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress. |
| CVE-2021-37781 | MEDIUM | 5.4 | 0.4% | Oct 28, 2022 | Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php. |
| CVE-2021-35388 | MEDIUM | 5.4 | 0.4% | Oct 28, 2022 | Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php. |
| CVE-2021-36206 | MEDIUM | 6.1 | 0.4% | Oct 28, 2022 | All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to by... |
| CVE-2021-45476 | MEDIUM | 4.7 | 0.4% | Oct 27, 2022 | Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnera... |
| CVE-2021-45475 | MEDIUM | 5.3 | 0.5% | Oct 27, 2022 | Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosur... |
| CVE-2021-45925 | MEDIUM | 5.3 | 0.5% | Oct 24, 2022 | Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. Th... |
| CVE-2021-44776 | MEDIUM | 5.3 | 0.4% | Oct 24, 2022 | A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbit... |
| CVE-2021-44769 | MEDIUM | 6.5 | 0.4% | Oct 24, 2022 | An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Deni... |
| CVE-2021-26732 | MEDIUM | 5.3 | 0.4% | Oct 24, 2022 | A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitr... |
| CVE-2021-33231 | MEDIUM | 5.4 | 0.6% | Oct 20, 2022 | Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote a... |
| CVE-2021-36201 | MEDIUM | 5.3 | 0.5% | Oct 11, 2022 | Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versi... |
| CVE-2021-36915 | MEDIUM | 4.3 | 0.2% | Oct 11, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows upload... |
| CVE-2021-36899 | MEDIUM | 4.8 | 0.4% | Oct 11, 2022 | Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Boos... |
| CVE-2021-35226 | MEDIUM | 6.5 | 0.4% | Oct 10, 2022 | An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Informatio... |
| CVE-2021-25044 | MEDIUM | 6.1 | 0.5% | Oct 10, 2022 | The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage pa... |
| CVE-2021-36865 | MEDIUM | 4.3 | 0.4% | Sep 30, 2022 | Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPres... |
| CVE-2021-36855 | MEDIUM | 6.1 | 0.2% | Sep 30, 2022 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at W... |
| CVE-2021-36839 | MEDIUM | 4.8 | 0.4% | Sep 30, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now