2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22934 | HIGH | 7.2 | 4.7% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Co... |
| CVE-2021-22933 | MEDIUM | 6.5 | 1.4% | Aug 16, 2021 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary... |
| CVE-2021-22932 | HIGH | 7.5 | 0.4% | Aug 16, 2021 | An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes... |
| CVE-2021-22931 | CRITICAL | 9.8 | 22.0% | Aug 16, 2021 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to miss... |
| CVE-2021-0114 | MEDIUM | 6.7 | 0.3% | Aug 16, 2021 | Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an... |
| CVE-2021-38758 | HIGH | 7.5 | 2.3% | Aug 16, 2021 | Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.ph... |
| CVE-2021-38757 | MEDIUM | 6.1 | 0.9% | Aug 16, 2021 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. |
| CVE-2021-38756 | MEDIUM | 6.1 | 0.7% | Aug 16, 2021 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php. |
| CVE-2021-38755 | MEDIUM | 5.3 | 1.0% | Aug 16, 2021 | Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php. |
| CVE-2021-38754 | CRITICAL | 9.8 | 1.8% | Aug 16, 2021 | SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php. |
| CVE-2021-38753 | CRITICAL | 9.8 | 1.5% | Aug 16, 2021 | An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain ... |
| CVE-2021-38752 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an a... |
| CVE-2021-38751 | MEDIUM | 4.3 | 2.5% | Aug 16, 2021 | A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha... |
| CVE-2021-38607 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input. |
| CVE-2021-35395 | CRITICAL | 9.8 | 98.1% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be u... |
| CVE-2021-35394 | CRITICAL | 9.8 | 99.9% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as... |
| CVE-2021-35393 | CRITICAL | 9.8 | 70.3% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP... |
| CVE-2021-35392 | HIGH | 7.5 | 83.2% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP... |
| CVE-2021-24548 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in t... |
| CVE-2021-24541 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which cou... |
| CVE-2021-24540 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which... |
| CVE-2021-24538 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or B... |
| CVE-2021-24536 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and... |
| CVE-2021-24535 | MEDIUM | 6.1 | 0.4% | Aug 16, 2021 | The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising... |
| CVE-2021-24534 | MEDIUM | 5.4 | 0.6% | Aug 16, 2021 | The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before out... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now