2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25209 | CRITICAL | 9.8 | 1.3% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbit... |
| CVE-2021-25205 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL ... |
| CVE-2021-3540 | HIGH | 7.2 | 3.3% | Jul 22, 2021 | By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions... |
| CVE-2021-3198 | HIGH | 7.2 | 3.3% | Jul 22, 2021 | By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivan... |
| CVE-2021-3619 | MEDIUM | 4.8 | 0.6% | Jul 22, 2021 | Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, ... |
| CVE-2021-31581 | MEDIUM | 4.4 | 1.2% | Jul 22, 2021 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Co... |
| CVE-2021-31580 | CRITICAL | 9.8 | 3.0% | Jul 22, 2021 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH cha... |
| CVE-2021-31579 | CRITICAL | 9.8 | 1.3% | Jul 22, 2021 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This iss... |
| CVE-2021-27332 | MEDIUM | 6.1 | 0.9% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke... |
| CVE-2021-26224 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject ar... |
| CVE-2021-26223 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute... |
| CVE-2021-25212 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrar... |
| CVE-2021-25210 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitra... |
| CVE-2021-36222 | HIGH | 7.5 | 10.3% | Jul 22, 2021 | ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.... |
| CVE-2021-35942 | CRITICAL | 9.1 | 2.7% | Jul 22, 2021 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in... |
| CVE-2021-35464 | CRITICAL | 9.8 | 100.0% | Jul 22, 2021 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa... |
| CVE-2021-35063 | HIGH | 7.5 | 2.0% | Jul 22, 2021 | Suricata before 5.0.7 and 6.x before 6.0.3 has a "critical evasion." |
| CVE-2021-33032 | CRITICAL | 10 | 52.2% | Jul 22, 2021 | A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and includi... |
| CVE-2021-26226 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute... |
| CVE-2021-25202 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitr... |
| CVE-2021-25197 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to in... |
| CVE-2021-37403 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w... |
| CVE-2021-37402 | MEDIUM | 6.1 | 0.8% | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the l... |
| CVE-2021-33478 | MEDIUM | 6.8 | 0.3% | Jul 22, 2021 | The TrustZone implementation in certain Broadcom MediaxChange firmware could allow an unauthenticated, physically proxim... |
| CVE-2021-29657 | HIGH | 7.4 | 0.4% | Jul 22, 2021 | arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now