2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27949 | MEDIUM | 6.1 | 0.6% | Mar 15, 2021 | Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools. |
| CVE-2021-27948 | HIGH | 7.2 | 0.9% | Mar 15, 2021 | SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3). |
| CVE-2021-27947 | HIGH | 7.2 | 0.9% | Mar 15, 2021 | SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3). |
| CVE-2021-27946 | HIGH | 8.8 | 4.2% | Mar 15, 2021 | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). |
| CVE-2021-27890 | HIGH | 8.8 | 10.6% | Mar 15, 2021 | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. |
| CVE-2021-22191 | HIGH | 8.8 | 3.6% | Mar 15, 2021 | Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet i... |
| CVE-2021-20286 | LOW | 2.7 | 1.1% | Mar 15, 2021 | A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service... |
| CVE-2021-27889 | MEDIUM | 6.1 | 5.1% | Mar 15, 2021 | Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages. |
| CVE-2021-27817 | CRITICAL | 9.8 | 3.2% | Mar 15, 2021 | A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar w... |
| CVE-2021-27695 | MEDIUM | 6.1 | 3.0% | Mar 15, 2021 | Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbit... |
| CVE-2021-27381 | HIGH | 7.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ... |
| CVE-2021-27380 | HIGH | 7.8 | 1.4% | Mar 15, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ... |
| CVE-2021-25676 | HIGH | 7.5 | 1.3% | Mar 15, 2021 | A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC... |
| CVE-2021-25675 | MEDIUM | 5.5 | 0.2% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste... |
| CVE-2021-25674 | MEDIUM | 5.5 | 0.2% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste... |
| CVE-2021-25673 | MEDIUM | 5.5 | 0.2% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste... |
| CVE-2021-25672 | HIGH | 8.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Passwo... |
| CVE-2021-25667 | HIGH | 8.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions ... |
| CVE-2021-23357 | MEDIUM | 5.3 | 0.5% | Mar 15, 2021 | All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOr... |
| CVE-2021-23356 | CRITICAL | 9.8 | 1.1% | Mar 15, 2021 | This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible ... |
| CVE-2021-23355 | CRITICAL | 9.8 | 1.2% | Mar 15, 2021 | This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is p... |
| CVE-2021-3167 | MEDIUM | 6.5 | 1.1% | Mar 15, 2021 | In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster ser... |
| CVE-2021-20440 | MEDIUM | 4.3 | 0.7% | Mar 15, 2021 | IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recep... |
| CVE-2021-27893 | HIGH | 7 | 0.4% | Mar 15, 2021 | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. Connec... |
| CVE-2021-27892 | HIGH | 7.8 | 0.3% | Mar 15, 2021 | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affe... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now