2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27950HIGH8.8A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to exec...
CVE-2021-3613HIGH7.8OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL confi...
CVE-2021-3606HIGH7.8OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL c...
CVE-2021-36132HIGH8.8An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of t...
CVE-2021-36131MEDIUM4.8An XSS issue was discovered in the SportsTeams extension in MediaWiki through 1.36. Within several special pages, a priv...
CVE-2021-36130MEDIUM4.8An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related specia...
CVE-2021-36129MEDIUM4.3An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does...
CVE-2021-36128CRITICAL9.8An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for CentralAuth-issued suppre...
CVE-2021-36127MEDIUM4.3An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provid...
CVE-2021-36126CRITICAL9.8An issue was discovered in the AbuseFilter extension in MediaWiki through 1.36. If the MediaWiki:Abusefilter-blocker mes...
CVE-2021-36125HIGH7.5An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is ...
CVE-2021-35197HIGH7.5In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended...
CVE-2021-35029CRITICAL9.8An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versio...
CVE-2021-27455MEDIUM5.5Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project ...
CVE-2021-27412HIGH7.8Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read, which may allow an attac...
CVE-2021-35042CRITICAL9.8Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input ...
CVE-2021-26920MEDIUM6.5In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In...
CVE-2021-32731MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and in...
CVE-2021-32730MEDIUM5.7XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site re...
CVE-2021-32729MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability...
CVE-2021-28424MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated u...
CVE-2021-28423HIGH8.8Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated user...
CVE-2021-28127HIGH7.5An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
CVE-2021-35337MEDIUM4.3Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any att...
CVE-2021-27661HIGH8.8Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Contr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now