2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27950 | HIGH | 8.8 | 1.7% | Jul 2, 2021 | A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to exec... |
| CVE-2021-3613 | HIGH | 7.8 | 0.5% | Jul 2, 2021 | OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL confi... |
| CVE-2021-3606 | HIGH | 7.8 | 0.3% | Jul 2, 2021 | OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL c... |
| CVE-2021-36132 | HIGH | 8.8 | 1.0% | Jul 2, 2021 | An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of t... |
| CVE-2021-36131 | MEDIUM | 4.8 | 0.4% | Jul 2, 2021 | An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a priv... |
| CVE-2021-36130 | MEDIUM | 4.8 | 0.5% | Jul 2, 2021 | An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related specia... |
| CVE-2021-36129 | MEDIUM | 4.3 | 0.6% | Jul 2, 2021 | An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does... |
| CVE-2021-36128 | CRITICAL | 9.8 | 1.5% | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppre... |
| CVE-2021-36127 | MEDIUM | 4.3 | 0.7% | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provid... |
| CVE-2021-36126 | CRITICAL | 9.8 | 1.2% | Jul 2, 2021 | An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker mes... |
| CVE-2021-36125 | HIGH | 7.5 | 1.0% | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is ... |
| CVE-2021-35197 | HIGH | 7.5 | 1.9% | Jul 2, 2021 | In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended... |
| CVE-2021-35029 | CRITICAL | 9.8 | 2.3% | Jul 2, 2021 | An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versio... |
| CVE-2021-27455 | MEDIUM | 5.5 | 0.7% | Jul 2, 2021 | Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project ... |
| CVE-2021-27412 | HIGH | 7.8 | 1.0% | Jul 2, 2021 | Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attac... |
| CVE-2021-35042 | CRITICAL | 9.8 | 44.4% | Jul 2, 2021 | Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input ... |
| CVE-2021-26920 | MEDIUM | 6.5 | 9.5% | Jul 2, 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In... |
| CVE-2021-32731 | MEDIUM | 5.3 | 1.2% | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and in... |
| CVE-2021-32730 | MEDIUM | 5.7 | 0.6% | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site re... |
| CVE-2021-32729 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability... |
| CVE-2021-28424 | MEDIUM | 5.4 | 1.3% | Jul 1, 2021 | A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated u... |
| CVE-2021-28423 | HIGH | 8.8 | 2.4% | Jul 1, 2021 | Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated user... |
| CVE-2021-28127 | HIGH | 7.5 | 0.9% | Jul 1, 2021 | An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur. |
| CVE-2021-35337 | MEDIUM | 4.3 | 0.8% | Jul 1, 2021 | Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any att... |
| CVE-2021-27661 | HIGH | 8.8 | 0.8% | Jul 1, 2021 | Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Contr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now