2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27949MEDIUM6.1Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
CVE-2021-27948HIGH7.2SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).
CVE-2021-27947HIGH7.2SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
CVE-2021-27946HIGH8.8SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
CVE-2021-27890HIGH8.8SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
CVE-2021-22191HIGH8.8Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet i...
CVE-2021-20286LOW2.7A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service...
CVE-2021-27889MEDIUM6.1Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
CVE-2021-27817CRITICAL9.8A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar w...
CVE-2021-27695MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbit...
CVE-2021-27381HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2021-27380HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2021-25676HIGH7.5A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC...
CVE-2021-25675MEDIUM5.5A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste...
CVE-2021-25674MEDIUM5.5A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste...
CVE-2021-25673MEDIUM5.5A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste...
CVE-2021-25672HIGH8.8A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Passwo...
CVE-2021-25667HIGH8.8A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions ...
CVE-2021-23357MEDIUM5.3All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOr...
CVE-2021-23356CRITICAL9.8This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible ...
CVE-2021-23355CRITICAL9.8This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is p...
CVE-2021-3167MEDIUM6.5In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster ser...
CVE-2021-20440MEDIUM4.3IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recep...
CVE-2021-27893HIGH7SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. Connec...
CVE-2021-27892HIGH7.8SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now