2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22934HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Co...
CVE-2021-22933MEDIUM6.5A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary...
CVE-2021-22932HIGH7.5An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes...
CVE-2021-22931CRITICAL9.8Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to miss...
CVE-2021-0114MEDIUM6.7Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an...
CVE-2021-38758HIGH7.5Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.ph...
CVE-2021-38757MEDIUM6.1Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
CVE-2021-38756MEDIUM6.1Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
CVE-2021-38755MEDIUM5.3Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
CVE-2021-38754CRITICAL9.8SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
CVE-2021-38753CRITICAL9.8An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain ...
CVE-2021-38752MEDIUM5.4A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an a...
CVE-2021-38751MEDIUM4.3A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can cha...
CVE-2021-38607MEDIUM5.4Crocoblock JetEngine before 2.6.1 allows XSS by remote authenticated users via a custom form input.
CVE-2021-35395CRITICAL9.8Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be u...
CVE-2021-35394CRITICAL9.8Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as...
CVE-2021-35393CRITICAL9.8Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP...
CVE-2021-35392HIGH7.5Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP...
CVE-2021-24548MEDIUM5.4The Mimetic Books WordPress plugin through 0.2.13 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS) in t...
CVE-2021-24541MEDIUM5.4The Wonder PDF Embed WordPress plugin before 1.7 does not escape parameters of its wonderplugin_pdf shortcode, which cou...
CVE-2021-24540MEDIUM5.4The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which...
CVE-2021-24538MEDIUM5.4The Current Book WordPress plugin through 1.0.1 does not sanitize user input when an authenticated user adds Author or B...
CVE-2021-24536MEDIUM6.1The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and...
CVE-2021-24535MEDIUM6.1The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising...
CVE-2021-24534MEDIUM5.4The PhoneTrack Meu Site Manager WordPress plugin through 0.1 does not sanitise or escape its "php_id" setting before out...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now