2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26381 | HIGH | 7.1 | 0.1% | Feb 10, 2026 | Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping... |
| CVE-2021-47921 | HIGH | 7.1 | 0.7% | Feb 1, 2026 | Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipula... |
| CVE-2021-47920 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | WebMO Job Manager 20.0 contains a cross-site scripting vulnerability in search parameters that allows remote attackers t... |
| CVE-2021-47919 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Atta... |
| CVE-2021-47918 | HIGH | 8.8 | 0.5% | Feb 1, 2026 | Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL c... |
| CVE-2021-47917 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote atta... |
| CVE-2021-47916 | — | — | — | Feb 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2021-47915 | HIGH | 8.8 | 0.5% | Feb 1, 2026 | PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated ... |
| CVE-2021-47914 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted paramete... |
| CVE-2021-47913 | MEDIUM | 5.4 | 0.2% | Feb 1, 2026 | PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users... |
| CVE-2021-47912 | MEDIUM | 5.4 | 0.2% | Feb 1, 2026 | PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and ... |
| CVE-2021-47911 | MEDIUM | 5.4 | 0.2% | Feb 1, 2026 | Affiliate Pro 1.7 contains multiple reflected cross-site scripting vulnerabilities in the index module's input fields. A... |
| CVE-2021-47909 | HIGH | 8.6 | 0.3% | Feb 1, 2026 | Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modul... |
| CVE-2021-47908 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remo... |
| CVE-2021-47885 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment in... |
| CVE-2021-47856 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Easy Cart Shopping Cart 2021 contains a non-persistent cross-site scripting vulnerability in the search module's keyword... |
| CVE-2021-47902 | HIGH | 8.8 | 0.2% | Jan 27, 2026 | Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate dat... |
| CVE-2021-47901 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject ... |
| CVE-2021-47900 | CRITICAL | 9.8 | 0.6% | Jan 27, 2026 | Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to ... |
| CVE-2021-47906 | MEDIUM | 6.4 | 0.2% | Jan 23, 2026 | BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authe... |
| CVE-2021-47905 | MEDIUM | 6.1 | 0.2% | Jan 23, 2026 | MyBB Delete Account Plugin 1.4 contains a cross-site scripting vulnerability in the account deletion reason input field.... |
| CVE-2021-47904 | HIGH | 8.8 | 0.6% | Jan 23, 2026 | PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execut... |
| CVE-2021-47903 | HIGH | 8.8 | 1.4% | Jan 23, 2026 | LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app con... |
| CVE-2021-47899 | MEDIUM | 6.9 | 0.3% | Jan 23, 2026 | YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read l... |
| CVE-2021-47898 | HIGH | 8.5 | 0.1% | Jan 23, 2026 | Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSyst... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now