2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36431 | CRITICAL | 9.1 | 0.9% | Feb 3, 2023 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie informa... |
| CVE-2021-36426 | HIGH | 8.8 | 1.1% | Feb 3, 2023 | File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to inc... |
| CVE-2021-36425 | MEDIUM | 5.4 | 1.0% | Feb 3, 2023 | Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $fil... |
| CVE-2021-36424 | CRITICAL | 9.8 | 1.2% | Feb 3, 2023 | An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installatio... |
| CVE-2021-3809 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi... |
| CVE-2021-3808 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi... |
| CVE-2021-3439 | HIGH | 7.8 | 0.2% | Feb 1, 2023 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being re... |
| CVE-2021-22786 | HIGH | 7.5 | 0.6% | Feb 1, 2023 | A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on th... |
| CVE-2021-46873 | MEDIUM | 5.3 | 0.5% | Jan 29, 2023 | WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be abl... |
| CVE-2021-4315 | HIGH | 8.8 | 0.9% | Jan 28, 2023 | A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unkn... |
| CVE-2021-41231 | HIGH | 7.2 | 1.2% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to ... |
| CVE-2021-41144 | HIGH | 8.8 | 1.2% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the blo... |
| CVE-2021-41143 | HIGH | 7.2 | 1.3% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the cu... |
| CVE-2021-39217 | HIGH | 7.2 | 1.3% | Jan 27, 2023 | OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to exec... |
| CVE-2021-21395 | MEDIUM | 4.3 | 0.4% | Jan 27, 2023 | Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior... |
| CVE-2021-41989 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions. |
| CVE-2021-41988 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions. |
| CVE-2021-36686 | MEDIUM | 5.4 | 0.5% | Jan 26, 2023 | Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api... |
| CVE-2021-36539 | MEDIUM | 6.5 | 0.9% | Jan 26, 2023 | Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the Doc... |
| CVE-2021-28510 | HIGH | 7.5 | 1.0% | Jan 26, 2023 | For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invali... |
| CVE-2021-43449 | HIGH | 8.1 | 1.2% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor servic... |
| CVE-2021-43448 | MEDIUM | 5.3 | 1.0% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allo... |
| CVE-2021-43447 | HIGH | 7.5 | 1.3% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the docume... |
| CVE-2021-43446 | MEDIUM | 6.1 | 0.8% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the docume... |
| CVE-2021-43445 | CRITICAL | 9.8 | 1.7% | Jan 23, 2023 | ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now