2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25209CRITICAL9.8SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbit...
CVE-2021-25205CRITICAL9.8SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL ...
CVE-2021-3540HIGH7.2By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions...
CVE-2021-3198HIGH7.2By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivan...
CVE-2021-3619MEDIUM4.8Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, ...
CVE-2021-31581MEDIUM4.4The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Co...
CVE-2021-31580CRITICAL9.8The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH cha...
CVE-2021-31579CRITICAL9.8Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This iss...
CVE-2021-27332MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke...
CVE-2021-26224MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject ar...
CVE-2021-26223CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-25212CRITICAL9.8SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrar...
CVE-2021-25210CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitra...
CVE-2021-36222HIGH7.5ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1....
CVE-2021-35942CRITICAL9.1The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in...
CVE-2021-35464CRITICAL9.8ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa...
CVE-2021-35063HIGH7.5Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion."
CVE-2021-33032CRITICAL10A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and includi...
CVE-2021-26226CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-25202CRITICAL9.8SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitr...
CVE-2021-25197MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to in...
CVE-2021-37403MEDIUM6.1OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w...
CVE-2021-37402MEDIUM6.1OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the l...
CVE-2021-33478MEDIUM6.8The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proxim...
CVE-2021-29657HIGH7.4arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now