2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37316HIGH7.5SQL injection vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remot...
CVE-2021-37315CRITICAL9.1Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634...
CVE-2021-37311HIGH7.5Buffer Overflow vulnerability in fcitx5 5.0.8 allows attackers to cause a denial of service via crafted message to the a...
CVE-2021-37306HIGH7.5An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and vi...
CVE-2021-37305HIGH7.5An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and vi...
CVE-2021-37304HIGH7.5An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege an...
CVE-2021-37234MEDIUM6.5Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows re...
CVE-2021-36712MEDIUM5.4Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping functio...
CVE-2021-36570HIGH8.8Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to...
CVE-2021-36569HIGH8.8Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to...
CVE-2021-36546HIGH7.5Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path ...
CVE-2021-36545MEDIUM5.4Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyrigh...
CVE-2021-36544HIGH7.5Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in...
CVE-2021-36538MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run ar...
CVE-2021-36535MEDIUM5.5Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js f...
CVE-2021-36532HIGH8.1Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt pa...
CVE-2021-36503CRITICAL9.8SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat para...
CVE-2021-36493HIGH7.5Buffer Overflow vulnerability in pdfimages in xpdf 4.03 allows attackers to crash the application via crafted command.
CVE-2021-36489MEDIUM6.5Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA...
CVE-2021-36484CRITICAL9.8SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article pag...
CVE-2021-36444HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via fl...
CVE-2021-36443HIGH8.8Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token ve...
CVE-2021-36434CRITICAL9.1SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie informa...
CVE-2021-36433CRITICAL9.1SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie informa...
CVE-2021-36432HIGH7.5SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie informa...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now