2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25809 | MEDIUM | 5.3 | 0.9% | Jul 23, 2021 | UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() f... |
| CVE-2021-25808 | HIGH | 7.8 | 1.2% | Jul 23, 2021 | A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a cr... |
| CVE-2021-25791 | MEDIUM | 5.4 | 2.5% | Jul 23, 2021 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S... |
| CVE-2021-25790 | MEDIUM | 5.4 | 0.9% | Jul 23, 2021 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing... |
| CVE-2021-23412 | CRITICAL | 9.8 | 4.0% | Jul 23, 2021 | All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes... |
| CVE-2021-3159 | MEDIUM | 5.4 | 0.5% | Jul 23, 2021 | A stored cross site scripting (XSS) vulnerability in the /sys/attachment/uploaderServlet component of Landray EKP V12.0.... |
| CVE-2021-25208 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitra... |
| CVE-2021-25206 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbit... |
| CVE-2021-25204 | MEDIUM | 5.4 | 0.7% | Jul 23, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject ar... |
| CVE-2021-25203 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload t... |
| CVE-2021-25201 | HIGH | 7.5 | 1.5% | Jul 23, 2021 | SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL stateme... |
| CVE-2021-25207 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary cod... |
| CVE-2021-20333 | MEDIUM | 5.3 | 1.3% | Jul 23, 2021 | Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log e... |
| CVE-2021-26799 | MEDIUM | 6.1 | 1.0% | Jul 23, 2021 | Cross Site Scripting (XSS) vulnerability in admin/files/edit in Omeka Classic <=2.7 allows remote attackers to inject ar... |
| CVE-2021-24036 | CRITICAL | 9.8 | 3.3% | Jul 23, 2021 | Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds wri... |
| CVE-2021-32786 | MEDIUM | 6.1 | 2.4% | Jul 22, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-32785 | HIGH | 7.5 | 2.7% | Jul 22, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-34268 | MEDIUM | 4.6 | 0.4% | Jul 22, 2021 | An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial... |
| CVE-2021-34267 | MEDIUM | 4.6 | 0.4% | Jul 22, 2021 | An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial ... |
| CVE-2021-34262 | MEDIUM | 6.8 | 0.5% | Jul 22, 2021 | A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and... |
| CVE-2021-34261 | MEDIUM | 4.6 | 0.4% | Jul 22, 2021 | An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service d... |
| CVE-2021-34260 | MEDIUM | 6.8 | 0.5% | Jul 22, 2021 | A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.... |
| CVE-2021-34259 | MEDIUM | 6.8 | 0.5% | Jul 22, 2021 | A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 an... |
| CVE-2021-25213 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrar... |
| CVE-2021-25211 | CRITICAL | 9.8 | 1.9% | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now