2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-24472CRITICAL9.8The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional...
CVE-2021-37760CRITICAL9.8A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level ...
CVE-2021-37759CRITICAL9.8A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access l...
CVE-2021-37595CRITICAL9.8In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i...
CVE-2021-37594CRITICAL9.8In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i...
CVE-2021-37593CRITICAL9.1PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQ...
CVE-2021-37144CRITICAL9.1CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user...
CVE-2021-36624CRITICAL9.8Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that al...
CVE-2021-35458CRITICAL9.8Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s paramete...
CVE-2021-34166CRITICAL9.8A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authenticatio...
CVE-2021-34165CRITICAL9.8A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authenticatio...
CVE-2021-30124CRITICAL9.8The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attacker...
CVE-2021-25200CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbit...
CVE-2021-29781CRITICAL9.8IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an u...
CVE-2021-23418CRITICAL9.8The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse unt...
CVE-2021-21538CRITICAL10Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability...
CVE-2021-37578CRITICAL9.8Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provi...
CVE-2021-23417CRITICAL9.8All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
CVE-2021-20399CRITICAL9.1IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) att...
CVE-2021-37555CRITICAL9.8TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-1673...
CVE-2021-37478CRITICAL9.8In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, whic...
CVE-2021-37477CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `childre...
CVE-2021-37476CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` throu...
CVE-2021-37475CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `templat...
CVE-2021-37473CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now