2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3169 | CRITICAL | 9.8 | 2.8% | Jul 23, 2021 | An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an... |
| CVE-2021-23412 | CRITICAL | 9.8 | 4.0% | Jul 23, 2021 | All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes... |
| CVE-2021-25208 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitra... |
| CVE-2021-25206 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbit... |
| CVE-2021-25203 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload t... |
| CVE-2021-25207 | CRITICAL | 9.8 | 1.9% | Jul 23, 2021 | Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary cod... |
| CVE-2021-24036 | CRITICAL | 9.8 | 3.3% | Jul 23, 2021 | Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds wri... |
| CVE-2021-25213 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrar... |
| CVE-2021-25211 | CRITICAL | 9.8 | 1.9% | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, ... |
| CVE-2021-25209 | CRITICAL | 9.8 | 1.3% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbit... |
| CVE-2021-25205 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL ... |
| CVE-2021-31580 | CRITICAL | 9.8 | 3.0% | Jul 22, 2021 | The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH cha... |
| CVE-2021-31579 | CRITICAL | 9.8 | 1.3% | Jul 22, 2021 | Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This iss... |
| CVE-2021-26223 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute... |
| CVE-2021-25212 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrar... |
| CVE-2021-25210 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitra... |
| CVE-2021-35942 | CRITICAL | 9.1 | 2.7% | Jul 22, 2021 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in... |
| CVE-2021-35464 | CRITICAL | 9.8 | 100.0% | Jul 22, 2021 | ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa... |
| CVE-2021-33032 | CRITICAL | 10 | 52.2% | Jul 22, 2021 | A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and includi... |
| CVE-2021-26226 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute... |
| CVE-2021-25202 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitr... |
| CVE-2021-26232 | CRITICAL | 9.8 | 2.7% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary ... |
| CVE-2021-26231 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL ... |
| CVE-2021-26229 | CRITICAL | 9.8 | 1.5% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute... |
| CVE-2021-26228 | CRITICAL | 9.8 | 1.7% | Jul 22, 2021 | SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now