2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-47872HIGH7.1SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authen...
CVE-2021-47871HIGH8.8Hestia Control Panel 1.3.2 contains an arbitrary file write vulnerability that allows authenticated attackers to write f...
CVE-2021-47870MEDIUM5.4GetSimple CMS My SMTP Contact Plugin 1.1.2 suffers from a Stored Cross-Site Scripting (XSS) vulnerability. The plugin at...
CVE-2021-47869HIGH8.5Brother BRAdmin Professional 3.75 contains an unquoted service path vulnerability in the BRA_Scheduler service that allo...
CVE-2021-47868HIGH8.5WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the WPCommandFileService that allows local users to ...
CVE-2021-47867HIGH8.5WIN-PACK PRO4.8 contains an unquoted service path vulnerability in the ScheduleService that allows local users to potent...
CVE-2021-47866HIGH8.5WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in the GuardTourService that allows local users to pote...
CVE-2021-47865HIGH8.7ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating mult...
CVE-2021-47864HIGH8.5OSAS Traverse Extension 11 contains an unquoted service path vulnerability in the TravExtensionHostSvc service running w...
CVE-2021-47863HIGH8.5MacPaw Encrypto 1.0.1 contains an unquoted service path vulnerability in its Encrypto Service configuration that allows ...
CVE-2021-47862HIGH8.5Hi-Rez Studios 5.1.6.3 contains an unquoted service path vulnerability in the HiPatchService that allows local attackers...
CVE-2021-47861HIGH8.5Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute ...
CVE-2021-47860MEDIUM4.3GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attac...
CVE-2021-47859HIGH8.5ActivIdentity 8.2 contains an unquoted service path vulnerability in the ac.sharedstore service that allows local attack...
CVE-2021-47858HIGH7.2Genexis Platinum-4410 P4410-V2-1.31A contains a stored cross-site scripting vulnerability in the 'start_addr' parameter ...
CVE-2021-47857MEDIUM6.1Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in the calendar event subtitle field that allows ...
CVE-2021-47855HIGH7.2Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows ...
CVE-2021-47854CRITICAL9.8DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote a...
CVE-2021-47853Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2021-47852HIGH8.8Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modi...
CVE-2021-47851CRITICAL9.8Mini Mouse 9.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary commands thro...
CVE-2021-47850HIGH8.7Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files a...
CVE-2021-47849HIGH7.5Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories th...
CVE-2021-47848HIGH8.8Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQ...
CVE-2021-47846HIGH8.8Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login page...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now