2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-3169CRITICAL9.8An issue in Jumpserver before 2.6.2, before 2.5.4, before 2.4.5 allows attackers to create a connection token through an...
CVE-2021-23412CRITICAL9.8All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes...
CVE-2021-25208CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Travel Management System v 1.0 allows attackers to execute arbitra...
CVE-2021-25206CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Responsive Ordering System v 1.0 allows attackers to execute arbit...
CVE-2021-25203CRITICAL9.8Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload t...
CVE-2021-25207CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester E-Commerce Website v 1.0 allows attackers to execute arbitrary cod...
CVE-2021-24036CRITICAL9.8Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds wri...
CVE-2021-25213CRITICAL9.8SQL injection vulnerability in SourceCodester Travel Management System v 1.0 allows remote attackers to execute arbitrar...
CVE-2021-25211CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, ...
CVE-2021-25209CRITICAL9.8SQL injection vulnerability in SourceCodester Theme Park Ticketing System v 1.0 allows remote attackers to execute arbit...
CVE-2021-25205CRITICAL9.8SQL injection vulnerability in SourceCodester E-Commerce Website V 1.0 allows remote attackers to execute arbitrary SQL ...
CVE-2021-31580CRITICAL9.8The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH cha...
CVE-2021-31579CRITICAL9.8Akkadian Provisioning Manager Engine (PME) ships with a hard-coded credential, akkadianuser:haakkadianpassword. This iss...
CVE-2021-26223CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-25212CRITICAL9.8SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrar...
CVE-2021-25210CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitra...
CVE-2021-35942CRITICAL9.1The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in...
CVE-2021-35464CRITICAL9.8ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa...
CVE-2021-33032CRITICAL10A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and includi...
CVE-2021-26226CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-25202CRITICAL9.8SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitr...
CVE-2021-26232CRITICAL9.8SQL injection vulnerability in SourceCodester Simple College Website v 1.0 allows remote attackers to execute arbitrary ...
CVE-2021-26231CRITICAL9.8SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL ...
CVE-2021-26229CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...
CVE-2021-26228CRITICAL9.8SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now