2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26699MEDIUM5.4OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled b...
CVE-2021-26698MEDIUM6.1OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) w...
CVE-2021-26232CRITICAL9.8SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary ...
CVE-2021-26231CRITICAL9.8SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL ...
CVE-2021-26230MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke...
CVE-2021-26229CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-26228CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-26227MEDIUM6.1Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attacke...
CVE-2021-34700MEDIUM5.5A vulnerability in the CLI interface of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to re...
CVE-2021-26765CRITICAL9.8SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL sta...
CVE-2021-26764HIGH8.8SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL s...
CVE-2021-26762HIGH8.8SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL sta...
CVE-2021-23897Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2021-1618HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an auth...
CVE-2021-1617MEDIUM6.5Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an auth...
CVE-2021-1614MEDIUM5.3A vulnerability in the Multiprotocol Label Switching (MPLS) packet handling function of Cisco SD-WAN Software could allo...
CVE-2021-1601HIGH8.3Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to acce...
CVE-2021-1600HIGH8.3Multiple vulnerabilities in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to acce...
CVE-2021-1599MEDIUM5.4A vulnerability in the web-based management interface of Cisco Unified Customer Voice Portal (CVP) could allow an authen...
CVE-2021-1518HIGH8.8A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, re...
CVE-2021-34431MEDIUM6.5In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CO...
CVE-2021-29149MEDIUM6.2A local bypass security restrictions vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Ser...
CVE-2021-29148MEDIUM6.1A local cross-site scripting (XSS) vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Serie...
CVE-2021-29143HIGH7.2A remote execution of arbitrary commands vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch...
CVE-2021-22001HIGH7.5In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response whe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now