2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32859MEDIUM6.1The Baremetrics date range picker is a solution for selecting both date ranges and single dates from a single calender v...
CVE-2021-32858MEDIUM6.1esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-ht...
CVE-2021-32857MEDIUM6.1Cockpit is a content management system that allows addition of content management functionality to any site. In versions...
CVE-2021-32856MEDIUM6.1Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to...
CVE-2021-32855MEDIUM6.1Vditor is a browser-side Markdown editor. Versions prior to 3.8.7 are vulnerable to copy-paste cross-site scripting (XSS...
CVE-2021-32854MEDIUM6.1textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting ...
CVE-2021-32853CRITICAL9.6Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in versions 0.2...
CVE-2021-32852CRITICAL9Countly, a product analytics solution, is vulnerable to cross-site scripting prior to version 21.11 of the community edi...
CVE-2021-32851MEDIUM6.1Mind-elixir is a free, open source mind map core. Prior to version 0.18.1, mind-elixir is prone to cross-site scripting ...
CVE-2021-32850MEDIUM6.1jQuery MiniColors is a color picker built on jQuery. Prior to version 2.3.6, jQuery MiniColors is prone to cross-site sc...
CVE-2021-32848HIGH7.5Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide...
CVE-2021-32847MEDIUM6.5HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior, a malic...
CVE-2021-32846HIGH7.8HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vts...
CVE-2021-32845HIGH7.8HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper...
CVE-2021-32844MEDIUM5.5HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper...
CVE-2021-32843MEDIUM5.5HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper...
CVE-2021-26277CRITICAL9.8The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to per...
CVE-2021-3172HIGH8.1An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Servic...
CVE-2021-35261CRITICAL9.8File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker t...
CVE-2021-34182CRITICAL9.8An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
CVE-2021-34164HIGH8.8Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set p...
CVE-2021-33983HIGH7.8Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc...
CVE-2021-33950HIGH7.5An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function...
CVE-2021-33949CRITICAL9.8An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function...
CVE-2021-33948CRITICAL9.8SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the usernam...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now