2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-24472 | CRITICAL | 9.8 | 56.6% | Aug 2, 2021 | The OnAir2 WordPress theme before 3.9.9.2 and QT KenthaRadio WordPress plugin before 2.0.2 have exposed proxy functional... |
| CVE-2021-37760 | CRITICAL | 9.8 | 1.3% | Jul 31, 2021 | A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level ... |
| CVE-2021-37759 | CRITICAL | 9.8 | 1.3% | Jul 31, 2021 | A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access l... |
| CVE-2021-37595 | CRITICAL | 9.8 | 1.5% | Jul 30, 2021 | In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i... |
| CVE-2021-37594 | CRITICAL | 9.8 | 1.4% | Jul 30, 2021 | In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing i... |
| CVE-2021-37593 | CRITICAL | 9.1 | 5.2% | Jul 30, 2021 | PEEL Shopping version 9.4.0 allows remote SQL injection. A public user/guest (unauthenticated) can inject a malicious SQ... |
| CVE-2021-37144 | CRITICAL | 9.1 | 1.3% | Jul 30, 2021 | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user... |
| CVE-2021-36624 | CRITICAL | 9.8 | 3.4% | Jul 30, 2021 | Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that al... |
| CVE-2021-35458 | CRITICAL | 9.8 | 2.4% | Jul 30, 2021 | Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s paramete... |
| CVE-2021-34166 | CRITICAL | 9.8 | 2.9% | Jul 30, 2021 | A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authenticatio... |
| CVE-2021-34165 | CRITICAL | 9.8 | 2.8% | Jul 30, 2021 | A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authenticatio... |
| CVE-2021-30124 | CRITICAL | 9.8 | 3.0% | Jul 30, 2021 | The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attacker... |
| CVE-2021-25200 | CRITICAL | 9.8 | 1.9% | Jul 30, 2021 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbit... |
| CVE-2021-29781 | CRITICAL | 9.8 | 2.9% | Jul 30, 2021 | IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an u... |
| CVE-2021-23418 | CRITICAL | 9.8 | 1.6% | Jul 29, 2021 | The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse unt... |
| CVE-2021-21538 | CRITICAL | 10 | 1.7% | Jul 29, 2021 | Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability... |
| CVE-2021-37578 | CRITICAL | 9.8 | 4.1% | Jul 29, 2021 | Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provi... |
| CVE-2021-23417 | CRITICAL | 9.8 | 1.1% | Jul 28, 2021 | All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function. |
| CVE-2021-20399 | CRITICAL | 9.1 | 1.8% | Jul 27, 2021 | IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) att... |
| CVE-2021-37555 | CRITICAL | 9.8 | 1.4% | Jul 26, 2021 | TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-1673... |
| CVE-2021-37478 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, whic... |
| CVE-2021-37477 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `childre... |
| CVE-2021-37476 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` throu... |
| CVE-2021-37475 | CRITICAL | 9.8 | 2.5% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `templat... |
| CVE-2021-37473 | CRITICAL | 9.8 | 2.2% | Jul 26, 2021 | In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now