2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25809MEDIUM5.3UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() f...
CVE-2021-25808HIGH7.8A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a cr...
CVE-2021-25791MEDIUM5.4Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S...
CVE-2021-25790MEDIUM5.4Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing...
CVE-2021-23412CRITICAL9.8All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes...
CVE-2021-3159MEDIUM5.4A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0....
CVE-2021-25208CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitra...
CVE-2021-25206CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbit...
CVE-2021-25204MEDIUM5.4Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject ar...
CVE-2021-25203CRITICAL9.8Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload t...
CVE-2021-25201HIGH7.5SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL stateme...
CVE-2021-25207CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary cod...
CVE-2021-20333MEDIUM5.3Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log e...
CVE-2021-26799MEDIUM6.1Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject ar...
CVE-2021-24036CRITICAL9.8Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds wri...
CVE-2021-32786MEDIUM6.1mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-32785HIGH7.5mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-34268MEDIUM4.6An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial...
CVE-2021-34267MEDIUM4.6An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial ...
CVE-2021-34262MEDIUM6.8A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and...
CVE-2021-34261MEDIUM4.6An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service d...
CVE-2021-34260MEDIUM6.8A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1....
CVE-2021-34259MEDIUM6.8A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 an...
CVE-2021-25213CRITICAL9.8SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrar...
CVE-2021-25211CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now