2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-47830MEDIUM6.5GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can cra...
CVE-2021-47817MEDIUM5.4OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers ca...
CVE-2021-47802HIGH8.7Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers...
CVE-2021-47778HIGH7.2GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator c...
CVE-2021-47770HIGH8.8OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to...
CVE-2021-47748CRITICAL9.8Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell com...
CVE-2021-47746HIGH8.6NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files...
CVE-2021-47847HIGH8.5Disk Sorter Server 13.6.12 contains an unquoted service path vulnerability in its binary path configuration that allows ...
CVE-2021-47845HIGH8.5Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows...
CVE-2021-47844MEDIUM6.1Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind ma...
CVE-2021-47842HIGH7.2StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts...
CVE-2021-47841MEDIUM6.1SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into ...
CVE-2021-47840HIGH7.2Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payload...
CVE-2021-47839HIGH7.2Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts i...
CVE-2021-47838HIGH7.2Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads...
CVE-2021-47837HIGH7.2Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payl...
CVE-2021-47836MEDIUM6.1Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thr...
CVE-2021-47835HIGH7.2Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads...
CVE-2021-47834MEDIUM6.4Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject ma...
CVE-2021-47833HIGH8.5WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local atta...
CVE-2021-47832Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate.
CVE-2021-47831HIGH7.5Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowin...
CVE-2021-47829HIGH8.5DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local...
CVE-2021-47828HIGH8.5BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers c...
CVE-2021-47827HIGH7.5WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now