2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36396 | HIGH | 7.5 | 1.4% | Mar 6, 2023 | In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictio... |
| CVE-2021-36395 | HIGH | 7.5 | 0.7% | Mar 6, 2023 | In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion de... |
| CVE-2021-36394 | CRITICAL | 9.8 | 7.0% | Mar 6, 2023 | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. |
| CVE-2021-36393 | CRITICAL | 9.8 | 52.3% | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. |
| CVE-2021-36392 | CRITICAL | 9.8 | 0.8% | Mar 6, 2023 | In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses. |
| CVE-2021-35377 | MEDIUM | 6.1 | 0.4% | Mar 6, 2023 | Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code ... |
| CVE-2021-4329 | CRITICAL | 9.8 | 2.3% | Mar 5, 2023 | A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some... |
| CVE-2021-36689 | MEDIUM | 5.5 | 0.3% | Mar 4, 2023 | An issue discovered in com.samourai.wallet.PinEntryActivity.java in Streetside Samourai Wallet 0.99.96i allows attackers... |
| CVE-2021-4328 | CRITICAL | 9.8 | 0.7% | Mar 2, 2023 | A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function good... |
| CVE-2021-3854 | CRITICAL | 9.8 | 0.6% | Mar 2, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Us... |
| CVE-2021-45479 | MEDIUM | 5.4 | 0.4% | Mar 2, 2023 | Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Aut... |
| CVE-2021-45478 | MEDIUM | 6.5 | 0.6% | Mar 2, 2023 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collec... |
| CVE-2021-45477 | MEDIUM | 6.5 | 0.6% | Mar 2, 2023 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collec... |
| CVE-2021-4327 | CRITICAL | 9.8 | 0.9% | Mar 1, 2023 | A vulnerability was found in SerenityOS. It has been rated as critical. Affected by this issue is the function initializ... |
| CVE-2021-4326 | HIGH | 7.8 | 0.3% | Mar 1, 2023 | A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands... |
| CVE-2021-3855 | HIGH | 8.8 | 1.9% | Mar 1, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Manag... |
| CVE-2021-22283 | MEDIUM | 5.5 | 0.2% | Feb 28, 2023 | Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 s... |
| CVE-2021-46841 | MEDIUM | 5.9 | 0.5% | Feb 27, 2023 | This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.... |
| CVE-2021-32302 | MEDIUM | 6.1 | 0.6% | Feb 27, 2023 | Cross Site Scripting vulnerability in IRZ Electronics RUH2 GSM router allows attacker to obtain sensitive information vi... |
| CVE-2021-3329 | MEDIUM | 6.5 | 0.6% | Feb 26, 2023 | Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack |
| CVE-2021-35290 | HIGH | 7.2 | 0.9% | Feb 24, 2023 | File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /... |
| CVE-2021-34249 | HIGH | 7.5 | 1.2% | Feb 24, 2023 | SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive informatio... |
| CVE-2021-34248 | — | — | — | Feb 24, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-25905. Reason: This candidate is a duplicate of ... |
| CVE-2021-34167 | HIGH | 8.8 | 0.4% | Feb 24, 2023 | Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via... |
| CVE-2021-35370 | CRITICAL | 9.8 | 1.0% | Feb 24, 2023 | An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now