2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3878CRITICAL9.8corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2021-3875MEDIUM5.5vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3874MEDIUM6.5bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-37739HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas...
CVE-2021-37738HIGH7.5A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ...
CVE-2021-39349MEDIUM4.8The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation an...
CVE-2021-39345MEDIUM4.8The HAL WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitizat...
CVE-2021-39344MEDIUM4.8The KJM Admin Notices WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation...
CVE-2021-39338MEDIUM4.8The MyBB Cross-Poster WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation...
CVE-2021-39337MEDIUM4.8The job-portal WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sa...
CVE-2021-39336MEDIUM4.8The Job Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and s...
CVE-2021-39335MEDIUM4.8The WpGenius Job Listing WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validat...
CVE-2021-39334MEDIUM4.8The Job Board Vanila WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-39332MEDIUM4.8The Business Manager WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-38431MEDIUM4.3An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose proj...
CVE-2021-37737HIGH8.8A remote SQL injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manag...
CVE-2021-37736CRITICAL9.8A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Poli...
CVE-2021-42336MEDIUM4.3The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remot...
CVE-2021-42335MEDIUM5.4Easytest bulletin board management function of online learning platform does not filter special characters. After obtain...
CVE-2021-42334HIGH8.8The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL...
CVE-2021-42333HIGH8.8The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL c...
CVE-2021-42332MEDIUM4.3The “List View” function of ShinHer StudyOnline System is not under authority control. After logging in with user’s priv...
CVE-2021-42331MEDIUM5.4The “Study Edit” function of ShinHer StudyOnline System does not perform permission control. After logging in with user’...
CVE-2021-42330HIGH8.8The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user...
CVE-2021-42329MEDIUM5.4The “List_Add” function of message board of ShinHer StudyOnline System does not filter special characters in the title p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now