2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37596 | MEDIUM | 6.1 | 0.6% | Jul 30, 2021 | Telegram Web K Alpha 0.6.1 allows XSS via a document name. |
| CVE-2021-37595 | CRITICAL | 9.8 | 1.5% | Jul 30, 2021 | In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i... |
| CVE-2021-37594 | CRITICAL | 9.8 | 1.4% | Jul 30, 2021 | In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i... |
| CVE-2021-37593 | CRITICAL | 9.1 | 5.2% | Jul 30, 2021 | PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQ... |
| CVE-2021-37588 | MEDIUM | 5.9 | 0.9% | Jul 30, 2021 | In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data. |
| CVE-2021-37587 | MEDIUM | 6.5 | 0.8% | Jul 30, 2021 | In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data. |
| CVE-2021-37144 | CRITICAL | 9.1 | 1.3% | Jul 30, 2021 | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user... |
| CVE-2021-36983 | HIGH | 7.8 | 0.5% | Jul 30, 2021 | replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/... |
| CVE-2021-36766 | HIGH | 7.2 | 3.7% | Jul 30, 2021 | Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/d... |
| CVE-2021-36754 | HIGH | 7.5 | 64.9% | Jul 30, 2021 | PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE ... |
| CVE-2021-36624 | CRITICAL | 9.8 | 3.4% | Jul 30, 2021 | Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that al... |
| CVE-2021-36621 | HIGH | 8.1 | 2.1% | Jul 30, 2021 | Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is v... |
| CVE-2021-36605 | MEDIUM | 5.4 | 0.6% | Jul 30, 2021 | engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user lis... |
| CVE-2021-36386 | HIGH | 7.5 | 2.6% | Jul 30, 2021 | report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, w... |
| CVE-2021-36004 | HIGH | 8.8 | 2.2% | Jul 30, 2021 | Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. A... |
| CVE-2021-35479 | MEDIUM | 5.4 | 13.2% | Jul 30, 2021 | Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log functio... |
| CVE-2021-35478 | MEDIUM | 5.4 | 76.6% | Jul 30, 2021 | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. ... |
| CVE-2021-35472 | HIGH | 8.8 | 1.7% | Jul 30, 2021 | An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spo... |
| CVE-2021-35458 | CRITICAL | 9.8 | 2.4% | Jul 30, 2021 | Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s paramete... |
| CVE-2021-34802 | HIGH | 8.8 | 1.0% | Jul 30, 2021 | A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow ... |
| CVE-2021-34166 | CRITICAL | 9.8 | 2.9% | Jul 30, 2021 | A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authenticatio... |
| CVE-2021-34165 | CRITICAL | 9.8 | 2.8% | Jul 30, 2021 | A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authenticatio... |
| CVE-2021-32610 | HIGH | 7.1 | 73.4% | Jul 30, 2021 | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability ... |
| CVE-2021-32558 | HIGH | 7.5 | 9.1% | Jul 30, 2021 | An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x befor... |
| CVE-2021-31878 | MEDIUM | 6.5 | 2.4% | Jul 30, 2021 | An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now