2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37596MEDIUM6.1Telegram Web K Alpha 0.6.1 allows XSS via a document name.
CVE-2021-37595CRITICAL9.8In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i...
CVE-2021-37594CRITICAL9.8In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i...
CVE-2021-37593CRITICAL9.1PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQ...
CVE-2021-37588MEDIUM5.9In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.
CVE-2021-37587MEDIUM6.5In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
CVE-2021-37144CRITICAL9.1CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user...
CVE-2021-36983HIGH7.8replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/...
CVE-2021-36766HIGH7.2Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/d...
CVE-2021-36754HIGH7.5PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE ...
CVE-2021-36624CRITICAL9.8Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that al...
CVE-2021-36621HIGH8.1Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is v...
CVE-2021-36605MEDIUM5.4engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user lis...
CVE-2021-36386HIGH7.5report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, w...
CVE-2021-36004HIGH8.8Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. A...
CVE-2021-35479MEDIUM5.4Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log functio...
CVE-2021-35478MEDIUM5.4Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. ...
CVE-2021-35472HIGH8.8An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spo...
CVE-2021-35458CRITICAL9.8Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s paramete...
CVE-2021-34802HIGH8.8A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow ...
CVE-2021-34166CRITICAL9.8A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authenticatio...
CVE-2021-34165CRITICAL9.8A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authenticatio...
CVE-2021-32610HIGH7.1In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability ...
CVE-2021-32558HIGH7.5An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x befor...
CVE-2021-31878MEDIUM6.5An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now