2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-44081HIGH7.5A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 character...
CVE-2021-44581HIGH7.5An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.
CVE-2021-43103HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote m...
CVE-2021-43102HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote ma...
CVE-2021-43101HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a...
CVE-2021-43100HIGH7.2A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote m...
CVE-2021-43098HIGH7.2A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.
CVE-2021-43097HIGH7.2A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a ma...
CVE-2021-25068HIGH7.2The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter wh...
CVE-2021-25064HIGH7.2The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a...
CVE-2021-24962HIGH8.8The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to ...
CVE-2021-44124HIGH7.5Hiby Music Hiby OS R3 Pro 1.5 and 1.6 is vulnerable to Directory Traversal. The HTTP Server does not have enough input d...
CVE-2021-26601HIGH8.1ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
CVE-2021-40905HIGH8.8The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uplo...
CVE-2021-40904HIGH8.8The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dok...
CVE-2021-44683HIGH8.2The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open functi...
CVE-2021-44905HIGH8.2Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attac...
CVE-2021-4202HIGH7A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kern...
CVE-2021-4157HIGH8An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users...
CVE-2021-44477HIGH7.5GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD paramete...
CVE-2021-44462HIGH7.1This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionR...
CVE-2021-3814HIGH7.5It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut...
CVE-2021-3567HIGH7.5A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-...
CVE-2021-3422HIGH7.5The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk En...
CVE-2021-35254HIGH8.8SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds ha...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now