2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26381HIGH7.1Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping...
CVE-2021-47921HIGH7.1Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipula...
CVE-2021-47920MEDIUM5.4WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers t...
CVE-2021-47919MEDIUM5.4Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Atta...
CVE-2021-47918HIGH8.8Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL c...
CVE-2021-47917MEDIUM5.4Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote atta...
CVE-2021-47916Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-47915HIGH8.8PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated ...
CVE-2021-47914MEDIUM5.4PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted paramete...
CVE-2021-47913MEDIUM5.4PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users...
CVE-2021-47912MEDIUM5.4PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and ...
CVE-2021-47911MEDIUM5.4Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. A...
CVE-2021-47909HIGH8.6Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modul...
CVE-2021-47908MEDIUM6.4Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remo...
CVE-2021-47885MEDIUM6.4Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment in...
CVE-2021-47856MEDIUM6.4Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword...
CVE-2021-47902HIGH8.8Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate dat...
CVE-2021-47901CRITICAL9.8Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject ...
CVE-2021-47900CRITICAL9.8Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to ...
CVE-2021-47906MEDIUM6.4BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authe...
CVE-2021-47905MEDIUM6.1MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field....
CVE-2021-47904HIGH8.8PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execut...
CVE-2021-47903HIGH8.8LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app con...
CVE-2021-47899MEDIUM6.9YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read l...
CVE-2021-47898HIGH8.5Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSyst...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now