2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20750MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE EC-CUBE 3.0.0 to 3.0.18-p2 (EC-CUBE 3 series) and EC-CUBE 4.0.0 to 4.0.5-p...
CVE-2021-20749MEDIUM5.4Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7....
CVE-2021-20746MEDIUM5.4Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker t...
CVE-2021-20745HIGH7.8Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by load...
CVE-2021-20740HIGH8.8Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Ga...
CVE-2021-35513MEDIUM6.1Mermaid before 8.11.0 allows XSS when the antiscript feature is used.
CVE-2021-35502CRITICAL9.8app/View/Elements/genericElements/IndexTable/Fields/generic_field.ctp in MISP 2.4.144 does not sanitize certain data rel...
CVE-2021-25654HIGH7.8An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a loca...
CVE-2021-1073HIGH8.3NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to l...
CVE-2021-34427CRITICAL9.8In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessibl...
CVE-2021-33542HIGH7Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution ...
CVE-2021-33541HIGH7.5Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service ...
CVE-2021-33540HIGH7.3In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP acc...
CVE-2021-33539HIGH7.2In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in...
CVE-2021-33538HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable improper access control vulnerability exists ...
CVE-2021-33537HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable remote code execution vulnerability exists in...
CVE-2021-33536HIGH7.5In Weidmueller Industrial WLAN devices in multiple versions an exploitable denial-of-service vulnerability exists in Ser...
CVE-2021-33535HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_...
CVE-2021-33534HIGH7.2In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the...
CVE-2021-33533HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the...
CVE-2021-33532HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the...
CVE-2021-33531HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable use of hard-coded credentials vulnerability e...
CVE-2021-33530HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in enc...
CVE-2021-33529HIGH7.5In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the servic...
CVE-2021-33528HIGH8.8In Weidmueller Industrial WLAN devices in multiple versions an exploitable privilege escalation vulnerability exists in ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now