2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40968MEDIUM6.1Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote...
CVE-2021-40928MEDIUM6.1Cross-site scripting (XSS) vulnerability in index.php in FlexTV beta development version allows remote attackers to inje...
CVE-2021-40927MEDIUM6.1Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers ...
CVE-2021-40926MEDIUM6.1Cross-site scripting (XSS) vulnerability in demos/demo.mysqli.php in getID3 1.X and v2.0.0-beta allows remote attackers ...
CVE-2021-40925MEDIUM6.1Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote a...
CVE-2021-40924MEDIUM6.1Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to i...
CVE-2021-40923MEDIUM6.1Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to i...
CVE-2021-40922MEDIUM6.1Cross-site scripting (XSS) vulnerability in install/index.php in bugs 1.8 and below version allows remote attackers to i...
CVE-2021-40921MEDIUM6.1Cross-site scripting (XSS) vulnerability in _contactform.inc.php in Detector 0.8.5 and below version allows remote attac...
CVE-2021-41647CRITICAL9.1An un-authenticated error-based and time-based blind SQL injection vulnerability exists in Kaushik Jadhav Online Food Or...
CVE-2021-3825CRITICAL9.6On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. ...
CVE-2021-29110MEDIUM5.4Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass an...
CVE-2021-29109MEDIUM6.1A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convi...
CVE-2021-29108HIGH8.8There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 a...
CVE-2021-41649CRITICAL9.8An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /homeaction.php c...
CVE-2021-41648HIGH7.5An un-authenticated SQL Injection exists in PuneethReddyHC online-shopping-system-advanced through the /action.php prId ...
CVE-2021-40960CRITICAL9.8Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd...
CVE-2021-41110CRITICAL9.8cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a D...
CVE-2021-35297HIGH7.8Scalabium dBase Viewer version 2.6 (Build 5.751) is vulnerable to remote code execution via a crafted DBF file that trig...
CVE-2021-41459HIGH7.5There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1008 in the nhmldmx_send_sample() function s...
CVE-2021-41457HIGH7.5There is a stack buffer overflow in MP4Box 1.1.0 at src/filters/dmx_nhml.c in nhmldmx_init_parsing which leads to a deni...
CVE-2021-41456HIGH7.5There is a stack buffer overflow in MP4Box v1.0.1 at src/filters/dmx_nhml.c:1004 in the nhmldmx_send_sample() function s...
CVE-2021-23893HIGH7.8Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow...
CVE-2021-3747HIGH7.8The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with inc...
CVE-2021-3710MEDIUM5.5An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now