2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-47830 | MEDIUM | 6.5 | 0.3% | Jan 21, 2026 | GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can cra... |
| CVE-2021-47817 | MEDIUM | 5.4 | 0.7% | Jan 21, 2026 | OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers ca... |
| CVE-2021-47802 | HIGH | 8.7 | 0.6% | Jan 21, 2026 | Tenda D151 and D301 routers contain an unauthenticated configuration download vulnerability that allows remote attackers... |
| CVE-2021-47778 | HIGH | 7.2 | 1.1% | Jan 21, 2026 | GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator c... |
| CVE-2021-47770 | HIGH | 8.8 | 0.6% | Jan 21, 2026 | OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to... |
| CVE-2021-47748 | CRITICAL | 9.8 | 1.0% | Jan 21, 2026 | Hasura GraphQL 1.3.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary shell com... |
| CVE-2021-47746 | HIGH | 8.6 | 0.7% | Jan 21, 2026 | NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files... |
| CVE-2021-47847 | HIGH | 8.5 | 0.2% | Jan 16, 2026 | Disk Sorter Server 13.6.12 contains an unquoted service path vulnerability in its binary path configuration that allows ... |
| CVE-2021-47845 | HIGH | 8.5 | 0.2% | Jan 16, 2026 | Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows... |
| CVE-2021-47844 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | Xmind 2020 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into mind ma... |
| CVE-2021-47842 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts... |
| CVE-2021-47841 | MEDIUM | 6.1 | 0.4% | Jan 16, 2026 | SnipCommand 0.1.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious payloads into ... |
| CVE-2021-47840 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payload... |
| CVE-2021-47839 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts i... |
| CVE-2021-47838 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads... |
| CVE-2021-47837 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payl... |
| CVE-2021-47836 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | Markdown Explorer 0.1.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious code thr... |
| CVE-2021-47835 | HIGH | 7.2 | 0.4% | Jan 16, 2026 | Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads... |
| CVE-2021-47834 | MEDIUM | 6.4 | 0.2% | Jan 16, 2026 | Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject ma... |
| CVE-2021-47833 | HIGH | 8.5 | 0.2% | Jan 16, 2026 | WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local atta... |
| CVE-2021-47832 | — | — | — | Jan 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate. |
| CVE-2021-47831 | HIGH | 7.5 | 0.3% | Jan 16, 2026 | Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowin... |
| CVE-2021-47829 | HIGH | 8.5 | 0.2% | Jan 16, 2026 | DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local... |
| CVE-2021-47828 | HIGH | 8.5 | 0.1% | Jan 16, 2026 | BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers c... |
| CVE-2021-47827 | HIGH | 7.5 | 0.4% | Jan 16, 2026 | WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now